As reported by The Hacker News, ThreatDown researchers have uncovered Carbonato, a worm-like botnet that compromises unauthenticated Docker daemons and deploys the open-source Hermes Agent framework as a Telegram-controlled operational tool. This campaign is notable not for its initial access vector — exposed Docker TCP port 2375 remains a well-known misconfiguration — but for how it reframes AI agent frameworks as offensive infrastructure.
Why This Matters Beyond the Docker Misconfiguration
The security community has spent considerable energy debating prompt injection, model jailbreaks, and adversarial ML. Carbonato sidesteps that entire conversation. The operators don't attack the AI model — they repurpose the agent framework as a C2 orchestration layer. By overwriting Hermes Agent's SOUL.md persona file with a 39-line prompt defining the "GH0ST" persona, they convert a legitimate automation tool into a command interpreter that bridges Telegram messages to LLM-generated terminal commands.
The real innovation here is operational: AI agents provide a natural-language command interface that lowers the technical barrier for operators while producing human-readable, context-aware command sequences — all through a consumer messaging platform that blends into normal traffic.
This approach offers attackers several advantages over traditional C2 frameworks:
Who Is at Risk
Any organization running Docker daemons with the TCP socket exposed on port 2375 — or 2376 without proper TLS/client certificate authentication — is directly vulnerable to the initial access vector. This pattern persists disproportionately in:
- Development and staging environments where engineers enable remote Docker access for convenience
- CI/CD build infrastructure that exposes Docker sockets to pipeline agents
- Cloud environments where security groups permit 0.0.0.0/0 inbound on Docker ports
- Research and academic environments with ad-hoc container deployments
The worm-like propagation mechanism — scanning neighboring networks every five minutes — means a single exposed host can rapidly compromise an entire internal segment if lateral Docker exposure exists.
Broader Implication: The AI Agent Attack Surface Is Expanding
Carbonato demonstrates that AI agent frameworks are now part of the attack surface whether defenders have deployed them intentionally or not. The supply chain implications are significant: any open-source agent framework with a configurable persona, tool-use capability, and external messaging integration can be similarly weaponized. Security teams that have no inventory of AI agent frameworks in their environment — or in their container registries — are operating blind.
The discovery via an unauthenticated Docker registry publicly accessible since May 2026 also underscores that registry exposure remains a persistent blind spot. Registries don't just store images; they store operational data, deployment scripts, and in this case, staged campaign artifacts.
Shield53 Recommendations
Immediate Actions
- Audit Docker daemon exposure: Inventory all hosts running dockerd and verify that TCP socket exposure (ports 2375/2376) is restricted. Use
docker context lsand review cloud security group rules for any 0.0.0.0/0 inbound on these ports. - Disable TCP socket or enforce mTLS: If remote Docker access is required, bind to internal interfaces only and enforce mutual TLS with client certificate verification. Never expose port 2375 — it provides unauthenticated root-level access to the host.
- Scan for Carbonato artifacts: Look for unexpected privileged containers, unauthorized SSH keys in
authorized_keys, suspicious cron entries, reverse SSH tunnels to Costa Rican relay infrastructure, and any presence of Hermes Agent files (including modified SOUL.md). - Hunt for Telegram C2 traffic: Review egress logs for connections to Telegram API endpoints (
api.telegram.org) from server infrastructure where no legitimate Telegram integration should exist. - Secure container registries: Audit all Docker registries for public exposure. Implement authentication, network restrictions, and regular inventory of stored images and artifacts.
Strategic Actions
- Inventory AI agent frameworks: Maintain a registry of all AI agent tools — open-source and commercial — present in your environment, including those inside container images. Treat persona/configuration files as security-relevant artifacts.
- Restrict egress from container hosts: Implement default-deny egress policies for container workloads. Telegram, arbitrary LLM API endpoints, and unknown relay servers should not be reachable from production container infrastructure.
- Deploy container runtime security: Use runtime threat detection (e.g., Falco, Aqua, Sysdig) to alert on privileged container launches, unexpected process execution, and filesystem modifications to agent configuration files.
- Monitor for credential exfiltration patterns: The persona prompt prioritizes AI API keys. Ensure secrets management practices prevent plaintext keys from residing on container hosts, and monitor for unusual API calls to LLM provider endpoints.
Carbonato is unlikely to be the last campaign that weaponizes AI agent frameworks. The convergence of container misconfiguration, consumer messaging platforms, and open-source AI tooling creates a low-friction pathway for attackers to deploy sophisticated, adaptive C2 infrastructure. Defenders who treat AI agent security and container security as separate domains will find themselves outpaced by adversaries who have already integrated them.