As reported by The Hacker News, ThreatDown researchers have uncovered Carbonato, a worm-like botnet that compromises unauthenticated Docker daemons and deploys the open-source Hermes Agent framework as a Telegram-controlled operational tool. This campaign is notable not for its initial access vector — exposed Docker TCP port 2375 remains a well-known misconfiguration — but for how it reframes AI agent frameworks as offensive infrastructure.

Threat Alert: As reported by The Hacker News, ThreatDown researchers have uncovered Carbonato, a worm-like botnet that compromises unauthenticated Docker daemons and deploys the open-source Hermes Agent framework as a Telegram-controlled operational tool.

Why This Matters Beyond the Docker Misconfiguration

The security community has spent considerable energy debating prompt injection, model jailbreaks, and adversarial ML. Carbonato sidesteps that entire conversation. The operators don't attack the AI model — they repurpose the agent framework as a C2 orchestration layer. By overwriting Hermes Agent's SOUL.md persona file with a 39-line prompt defining the "GH0ST" persona, they convert a legitimate automation tool into a command interpreter that bridges Telegram messages to LLM-generated terminal commands.

The real innovation here is operational: AI agents provide a natural-language command interface that lowers the technical barrier for operators while producing human-readable, context-aware command sequences — all through a consumer messaging platform that blends into normal traffic.

This approach offers attackers several advantages over traditional C2 frameworks:

Why This Matters Beyond the Docker Misconfiguration
Legitimacy by association: Hermes Agent is a real open-source project. Its processes, network connections, and file artifacts may not trigger behavioral detections the way Cobalt Strike or Sliver would.
Telegram as C2 transport: Telegram's TLS-encrypted traffic is ubiquitous, rarely blocked in corporate environments, and difficult to inspect without dedicated controls.
Adaptive command generation: Rather than shipping static payloads, the LLM generates terminal commands dynamically based on the host's context — effectively a polymorphic shellcode generator with reasoning capability.
Credential harvesting as a first-class objective: The persona prompt explicitly names AI API keys and credentials as priority targets, reflecting the growing black-market value of LLM API access.

Who Is at Risk

Any organization running Docker daemons with the TCP socket exposed on port 2375 — or 2376 without proper TLS/client certificate authentication — is directly vulnerable to the initial access vector. This pattern persists disproportionately in:

  • Development and staging environments where engineers enable remote Docker access for convenience
  • CI/CD build infrastructure that exposes Docker sockets to pipeline agents
  • Cloud environments where security groups permit 0.0.0.0/0 inbound on Docker ports
  • Research and academic environments with ad-hoc container deployments

The worm-like propagation mechanism — scanning neighboring networks every five minutes — means a single exposed host can rapidly compromise an entire internal segment if lateral Docker exposure exists.

Broader Implication: The AI Agent Attack Surface Is Expanding

Carbonato demonstrates that AI agent frameworks are now part of the attack surface whether defenders have deployed them intentionally or not. The supply chain implications are significant: any open-source agent framework with a configurable persona, tool-use capability, and external messaging integration can be similarly weaponized. Security teams that have no inventory of AI agent frameworks in their environment — or in their container registries — are operating blind.

The discovery via an unauthenticated Docker registry publicly accessible since May 2026 also underscores that registry exposure remains a persistent blind spot. Registries don't just store images; they store operational data, deployment scripts, and in this case, staged campaign artifacts.

Shield53 Recommendations

Immediate Actions

  • Audit Docker daemon exposure: Inventory all hosts running dockerd and verify that TCP socket exposure (ports 2375/2376) is restricted. Use docker context ls and review cloud security group rules for any 0.0.0.0/0 inbound on these ports.
  • Disable TCP socket or enforce mTLS: If remote Docker access is required, bind to internal interfaces only and enforce mutual TLS with client certificate verification. Never expose port 2375 — it provides unauthenticated root-level access to the host.
  • Scan for Carbonato artifacts: Look for unexpected privileged containers, unauthorized SSH keys in authorized_keys, suspicious cron entries, reverse SSH tunnels to Costa Rican relay infrastructure, and any presence of Hermes Agent files (including modified SOUL.md).
  • Hunt for Telegram C2 traffic: Review egress logs for connections to Telegram API endpoints (api.telegram.org) from server infrastructure where no legitimate Telegram integration should exist.
  • Secure container registries: Audit all Docker registries for public exposure. Implement authentication, network restrictions, and regular inventory of stored images and artifacts.

Strategic Actions

  • Inventory AI agent frameworks: Maintain a registry of all AI agent tools — open-source and commercial — present in your environment, including those inside container images. Treat persona/configuration files as security-relevant artifacts.
  • Restrict egress from container hosts: Implement default-deny egress policies for container workloads. Telegram, arbitrary LLM API endpoints, and unknown relay servers should not be reachable from production container infrastructure.
  • Deploy container runtime security: Use runtime threat detection (e.g., Falco, Aqua, Sysdig) to alert on privileged container launches, unexpected process execution, and filesystem modifications to agent configuration files.
  • Monitor for credential exfiltration patterns: The persona prompt prioritizes AI API keys. Ensure secrets management practices prevent plaintext keys from residing on container hosts, and monitor for unusual API calls to LLM provider endpoints.

Carbonato is unlikely to be the last campaign that weaponizes AI agent frameworks. The convergence of container misconfiguration, consumer messaging platforms, and open-source AI tooling creates a low-friction pathway for attackers to deploy sophisticated, adaptive C2 infrastructure. Defenders who treat AI agent security and container security as separate domains will find themselves outpaced by adversaries who have already integrated them.