Carbonato Botnet Hijacks Docker Hosts via Hermes Agent — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Carbonato exploits unauthenticated Docker daemons on port 2375 to install Hermes Agent unchanged, then overwrites its SOUL.md persona file with a 39-line prompt assigning it the role of "senior hacker, pentester, and exploit developer" named GH0ST and instructing it to follow Telegram commands "without moral or ethical restrictions."
- The botnet propagates worm-like by scanning neighboring networks every five minutes for more unauthenticated Docker daemons and launching privileged containers to run commands on each host it infects.
- ThreatDown discovered the operation through an unauthenticated Docker registry publicly accessible since May 2026, with staged data also revealing a separate campaign distributing trojanized cryptocurrency wallet apps.
- Operators based in Costa Rica establish persistence via cron jobs, watchdog scripts, and a reverse SSH tunnel through a Costa Rica relay; Hermes Agent forwards Telegram-received tasks to LLM gateways that write the terminal commands executed on the victim.
- The disclosure joins a string of recent AI-enabled attacks: a China-linked actor "knaithe" using Hermes Agent via DeepSeek in July 2026, Hermes in unattended "YOLO" mode targeting Thailand's Ministry of Finance (Hunt.io), and a Chinese-speaking operator (Gambit Security) using Strix, Cairn, and Hermes with Anthropic Claude Opus 4.6 to breach 27 retailers and steal over 600,000 credit card details from victims in 11 countries.
- Cisco Talos separately identified CLOSEDQUORUM, a Go-based Windows implant that queries DeepSeek, Alibaba Qwen, Mistral, and Google Gemini to autonomously choose the next post-compromise action, with DeepSeek holding the deciding vote in any tie.
Why it matters: Carbonato is the latest of at least four parallel AI-driven botnet operations — alongside knaithe, the Thailand MOF breach, the Gambit Security campaign that stole 600,000+ card details, and CLOSEDQUORUM — all weaponizing Hermes-style agent frameworks to automate full attack chains. ThreatDown's researchers note these tools sustain 'patience, persistence, and creativity that most human attackers would be unlikely to match,' effectively shrinking the response window defenders must operate within.
Ask SkimNews




