Carbonato Botnet Exploits Hermes AI Agent to Harvest Cloud API Keys from Unsecured Docker Nodes
A newly identified botnet dubbed Carbonato is leveraging the open‑source Hermes Agent AI framework to infiltrate Docker hosts that are left exposed on the internet, according to a report from Dark Reading. The malware uses Telegram as a command‑and‑control channel, issuing instructions to compromised containers and exfiltrating valuable artificial‑intelligence API keys stored on the hosts.
Hermes Agent, originally designed to simplify the deployment of AI workloads across containerized environments, provides a lightweight runtime that can execute arbitrary code. Attackers have repurposed this capability, packaging the agent within a malicious Docker image that can be pulled and launched on any system with an open Docker daemon. Once instantiated, the agent registers with a Telegram bot, allowing operators to send commands in real time.
The infection chain typically begins with a misconfigured Docker daemon that listens without authentication or is bound to a public interface. Scanners on the internet locate these hosts, then push the compromised image. After the container starts, the embedded Hermes Agent scans the host for stored credentials—particularly API keys for services such as OpenAI, Anthropic, or other generative‑AI platforms—and forwards them back through the Telegram channel.
AI service keys are high‑value targets because they can be used to generate large volumes of content at relatively low cost, enabling fraud, disinformation, or the creation of illicit material at scale. The theft of such keys also bypasses the usual billing safeguards, potentially leading to unexpected charges for the victim organizations. Security analysts note that the combination of a legitimate AI framework and a popular messaging app makes detection more difficult, as traffic may appear benign.
The emergence of Carbonato reflects a broader shift in botnet tactics toward cloud‑native infrastructure. While earlier networks focused on IoT devices or traditional web servers, the rapid adoption of container platforms has opened new attack surfaces. Docker’s ease of use often comes at the expense of rigorous security hygiene, and many organizations still run daemons with default settings, inadvertently exposing management APIs to the public.
Researchers recommend several mitigations: enforce authentication on Docker sockets, restrict network exposure through firewalls, employ secret‑management tools to keep API keys out of container images, and monitor outbound connections for unexpected Telegram traffic. The maintainers of Hermes Agent have been notified of the abuse, though the framework itself does not contain malicious code. As the threat landscape evolves, continuous auditing of container configurations will be essential to prevent similar repurposing of legitimate software for illicit ends.
Comments (0)
Be the first to comment.
Join the discussion