As reported by Dark Reading, the Carbonato botnet has begun deploying the open source Hermes Agent AI framework on compromised Docker hosts, using Telegram as a command channel and targeting AI API keys as a primary payload. This is a meaningful evolution — not because the individual techniques are novel, but because the composition signals where opportunistic threat actors are heading.

Threat Alert: As reported by Dark Reading, the Carbonato botnet has begun deploying the open source Hermes Agent AI framework on compromised Docker hosts, using Telegram as a command channel and targeting AI API keys as a primary payload.

The core attack chain is straightforward: find exposed Docker daemon APIs, deploy a container, and run Hermes Agent inside it. What changes the calculus is the agent layer. By wrapping command execution in an AI orchestration framework and routing control through Telegram, Carbonato gains a flexible, natural-language interface to its foothold. This lowers the operational skill floor for the operator and blurs traditional C2 detection patterns.

Why This Matters Beyond the Headline

Three things stand out to Shield53 analysts:

Why This Matters Beyond the Headline
AI API keys are now a loot category. Stolen keys to major LLM providers can be resold, abused for inference at scale, or used to power further automated attacks. Organizations rarely monitor key usage the way they monitor credentials or session tokens.
Telegram as C2 is operationally convenient and detection-poor. Many environments allow outbound TLS to messaging platforms. Blocking it broadly is rarely feasible, so detection must focus on behavior inside the host.
Open source AI agent frameworks are dual-use infrastructure. Hermes and similar projects are designed for legitimate automation, but their flexibility makes them attractive wrappers for post-exploitation. Defenders should assume adversaries will continue adopting these tools.

Who Is Most Exposed

Any organization running Docker daemons reachable from the internet — or from a broad internal CIDR — without authentication is at elevated risk. This remains one of the most consistently abused misconfigurations in cloud and self-hosted environments. Smaller teams, research labs, and CI/CD pipelines with ephemeral containers are frequent victims because exposure is often accidental and short-lived, but short-lived is enough.

The combination of an exposed container runtime and unmonitored AI API keys creates a compounding risk: the foothold is cheap and the loot is immediately monetizable.

Detection Considerations

Standard container runtime telemetry — process spawns, network egress, volume mounts — still applies, but look specifically for:

  • Unexpected docker run invocations originating from external IPs
  • Outbound TLS to Telegram API endpoints from container workloads that have no business need
  • Access to .env files, key vaults, or environment variables containing OPENAI_API_KEY, ANTHROPIC_API_KEY, or similar
  • Python or Node processes spawning shells after container startup, especially with Hermes Agent or similar package imports

Shield53 Recommendations

  • Close the primary gap. Ensure Docker daemons are never exposed without TLS and mutual authentication. Bind to a socket or Unix file, and place behind a VPN or zero-trust layer if remote access is required.
  • Inventory and rotate AI API keys. Treat LLM provider keys as secrets of equivalent sensitivity to cloud root credentials. Rotate any keys that may have been present on shared or exposed hosts.
  • Implement egress allow-listing for containers. Default-deny outbound traffic and explicitly allow only required endpoints. This neutralizes Telegram-based C2 and most exfiltration paths.
  • Deploy runtime container security tooling. Solutions that profile expected container behavior and alert on shell spawns, suspicious package imports, or anomalous network flows are more effective than signature-based controls here.
  • Monitor API key usage at the provider level. Most major AI providers expose usage dashboards and anomaly alerts. Enable them and review regularly for spikes from unexpected regions or workloads.

The Carbonato development is not a paradigm shift, but it is a clear indicator that threat actors are integrating AI tooling into existing playbooks faster than many defenders are adapting their monitoring to account for it. The mitigation is unglamorous — close exposed APIs, rotate keys, restrict egress — but the window between exposure and compromise remains measured in minutes, not days.