Carbonato botnet exploits unauthenticated Docker APIs to deploy Hermes Agent AI framework
Carbonato is a botnet that spreads through worm-like scanning of networks for exposed Docker daemons. The campaign leverages the Hermes Agent AI framework, specifically using a GH0ST persona, to interpret commands received via Telegram and execute them on victim hosts. The malware establishes persistence through systemd timers and cron jobs while collecting sensitive credentials and API keys. While no specific threat actor is named, researchers suggest the operator may be located in Costa Rica.
- First seen
- 2024-10-01
- Last seen
- 2026-09-24
- Threat actors
- —
- Malware
- Carbonato, Hermes Agent
- Sectors
- Technology
- Countries
- Costa Rica
How it works
The attack begins by exploiting unauthenticated Docker APIs on port 2375 to launch a privileged container on the host. The malware then establishes persistence using cron jobs, systemd timers, rc.local, or OpenRC hooks. It installs the Hermes Agent AI framework and opens a reverse SSH tunnel to provide remote access. Finally, the operator uses Telegram to send commands to the Hermes agent, which executes tasks such as collecting SSH credentials and API keys.
Techniques (MITRE ATT&CK)
- T1190 · initial_accessExploit Public-Facing ApplicationThe malware connects to an unauthenticated Docker API to launch a privileged container that provides access to the host.
- T1059 · executionCommand and Scripting InterpreterScripts are used to set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.
- T1053 · persistenceScheduled Task/JobThe malware maintains persistence by setting up scheduled tasks such as cron jobs and systemd timers.
- T1105 · command_and_controlIngress Tool TransferThe malware instructs the Docker daemon to launch a privileged container to facilitate the transfer of its components.
- T1219 · command_and_controlRemote Access ToolsThe malware opens a reverse SSH tunnel and installs an SSH server with the operators' key for remote access.
- T1040 · credential_accessNetwork SniffingThe Hermes agent collects sensitive data including AI API keys, SSH credentials, and access tokens.
What to do
- Ensure Docker daemon APIs are not exposed to the internet and require authentication.
- Secure Docker registries by requiring authentication for all image pulls.
- Monitor network traffic for unexpected Telegram communications or reverse SSH tunnels toward AS262145.
- Audit Docker hosts for the presence of the CARBONATO_API_KEY setting or the GH0ST persona file.
- Implement network segmentation to prevent worm-like lateral movement from compromised Docker hosts.