OffPerimeter · Threat advisories
Campaign advisory
lowPublished 2026-09-25 · 0 indicators

Carbonato botnet exploits unauthenticated Docker APIs to deploy Hermes Agent AI framework

Carbonato is a botnet that spreads through worm-like scanning of networks for exposed Docker daemons. The campaign leverages the Hermes Agent AI framework, specifically using a GH0ST persona, to interpret commands received via Telegram and execute them on victim hosts. The malware establishes persistence through systemd timers and cron jobs while collecting sensitive credentials and API keys. While no specific threat actor is named, researchers suggest the operator may be located in Costa Rica.

ShareXLinkedInWhatsApp
First seen
2024-10-01
Last seen
2026-09-24
Threat actors
—
Malware
Carbonato, Hermes Agent
Sectors
Technology
Countries
Costa Rica

How it works

The attack begins by exploiting unauthenticated Docker APIs on port 2375 to launch a privileged container on the host. The malware then establishes persistence using cron jobs, systemd timers, rc.local, or OpenRC hooks. It installs the Hermes Agent AI framework and opens a reverse SSH tunnel to provide remote access. Finally, the operator uses Telegram to send commands to the Hermes agent, which executes tasks such as collecting SSH credentials and API keys.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp