⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

September 28, 2026

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent Ravie LakshmananSep 28, 2026Malware / Cloud Security Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through Telegram, maintain persistence, and collect credentials." At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to propagate further. On each host, it installs Hermes Agent with instructions to follow operators' Telegram commands. The cybersecurity company…