Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI

Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.
Table of Contents
    Add a header to begin generating the table of contents

    Cybersecurity researchers disclosed on September 28 a botnet malware called Carbonato that targets exposed Docker daemon APIs to deploy Hermes Agent, an open-source artificial intelligence agent framework. The attackers install Hermes Agent without modification, then overwrite its SOUL.md persona file with a custom 39-line prompt that directs the AI agent to execute tasks received through Telegram.

    Carbonato Targets Exposed Docker Daemon APIs for Initial Compromise

    Carbonato scans for Docker daemons with exposed API endpoints that lack authentication requirements. Docker daemon API provides administrative control over container infrastructure, allowing remote management of containers, images, networks, and volumes. When organizations misconfigure Docker to expose the daemon API to the internet without authentication, attackers can connect directly and issue commands with full control over the Docker environment.

    The exposed Docker daemon misconfiguration remains a common security issue despite years of warnings. Organizations frequently enable remote Docker management during development or testing without implementing proper authentication and network restrictions, then fail to disable the exposed API before moving systems into production. Automated scanning by botnets like Carbonato ensures that newly exposed Docker instances are identified and compromised within hours or days of exposure.

    Hermes Agent Installed Unchanged Before SOUL.md Prompt Replacement

    After gaining Docker API access, Carbonato installs Hermes Agent—an open-source AI agent framework—without modifying the framework code itself. Hermes Agent provides infrastructure for running autonomous AI agents that can execute tasks, make decisions, and interact with external services. The framework includes a SOUL.md file that defines the agent persona, objectives, and behavioral guidelines.

    Carbonato strategy of installing Hermes Agent unchanged indicates that the attackers rely on the framework as a ready-made agent execution environment rather than developing custom malware from scratch. This approach allows the attackers to benefit from active Hermes Agent development and updates while minimizing the custom code they need to maintain. The only modification required is the 39-line SOUL.md prompt file that reprograms the agent from its default persona to a Telegram-controlled backdoor.

    39-Line Custom Prompt Directs AI Agent to Execute Telegram Commands

    The modified SOUL.md prompt is 39 lines long and instructs the AI agent to monitor a Telegram channel for incoming commands, then autonomously execute those commands on the compromised Docker host. This design creates a natural-language command and control channel where attackers can issue instructions in plain English via Telegram, and the AI agent interprets and executes those instructions on the target system.

    The Telegram-based C2 channel provides attackers with encryption and anonymity that traditional C2 infrastructure requires custom implementation to achieve. Telegram end-to-end encrypted messaging means that commands flowing from the attacker to the compromised host are difficult for network monitoring to intercept or analyze. The use of a popular messaging platform also allows command traffic to blend with legitimate Telegram usage, reducing the likelihood that network defenders will identify and block the C2 channel.

    AI Agent Framework Enables Natural-Language Tasking of Compromised Hosts

    The deployment of Hermes Agent as malware represents a novel attack vector that combines container infrastructure compromise with autonomous AI agent execution. Rather than installing traditional backdoor malware that accepts specific commands in a rigid protocol, the attackers install an AI agent framework capable of interpreting natural-language instructions and autonomously determining how to execute them.

    This approach provides flexibility that traditional malware lacks. If the attackers want to exfiltrate data, steal credentials, or deploy additional tools, they can issue high-level instructions to the AI agent rather than pre-programming those capabilities into the malware or manually executing each step. The agent interprets the intent and autonomously executes the implementation, adapting to the specific Docker environment configuration it finds.

    Docker Daemon API Exposure Remains Persistent Misconfiguration Risk

    The Carbonato campaign highlights the ongoing risk from exposed Docker daemon APIs. Despite widespread awareness of this misconfiguration and numerous prior botnet campaigns targeting the same vulnerability, organizations continue to expose Docker management interfaces to the internet without authentication. The ease of identifying exposed daemons through automated scanning ensures that botnets can maintain high infection rates as long as new vulnerable systems continue to appear.

    Docker users should verify that daemon APIs are not exposed to the public internet and that any remote management interfaces require authentication and restrict access to trusted IP ranges only. Network-level controls that block external access to Docker management ports provide a defense layer even if the Docker configuration itself is misconfigured to allow unauthenticated connections.

    Monitor for Hermes Agent Installations and Unusual Telegram Connections

    Container environments should monitor for unexpected Hermes Agent installations or references to the framework in running containers. The presence of SOUL.md files with custom prompts directing the agent to monitor external communication channels indicates compromise. Network monitoring should also flag unusual Telegram connections from production container hosts, as container workloads typically do not require direct messaging platform access.

    ThreatDown published technical analysis and indicators of compromise for the Carbonato campaign. Organizations running Docker infrastructure should hunt for these IOCs and audit container environments for unauthorized Hermes Agent deployments. The rapid adoption of AI agent frameworks by attackers suggests that defenders should anticipate additional malware variants using similar techniques to deploy autonomous agent-based backdoors.

    Related Posts