Carbonato Botnet Exploits Unsecured Docker Daemons to Deploy AI‑Powered Hermes Agent
A newly identified malware family dubbed Carbonato is weaponising artificial‑intelligence tools to hijack Docker hosts that are left exposed on the internet, security researchers reported. The botnet infiltrates systems running an unsecured Docker daemon, installs the Hermes Agent AI framework, and then commandeers the compromised machines for malicious purposes.
Carbonato operates by scanning for Docker daemons that are reachable without authentication, a configuration error that can arise when administrators neglect to bind the service to a local interface or to enforce TLS certificates. Once a vulnerable endpoint is located, the malware downloads the Hermes Agent—a lightweight AI platform designed for remote execution—and integrates it into the host’s container runtime. The agent then serves as a foothold, allowing the attackers to issue commands, download additional payloads, and potentially use the compromised servers as part of a larger distributed denial‑of‑service (DDoS) network or for cryptomining.
The emergence of this threat underscores a broader shift in cyber‑crime, where adversaries are increasingly coupling traditional infection vectors with AI‑enabled components to improve automation and adaptability. Hermes, originally created for legitimate edge‑computing and machine‑learning workloads, is being repurposed as a modular backdoor that can respond to commands in real time, making the botnet more resilient against takedown attempts. Analysts note that the use of an AI framework may also facilitate rapid re‑configuration of the malware’s behaviour based on the environment it infects.
Docker’s popularity for packaging applications has grown dramatically in recent years, but its flexibility can become a liability when default security settings are left untouched. Experts advise that organizations should enforce strong access controls on the Docker socket, enable mutual TLS authentication, and limit network exposure of the daemon. Regular audits of container orchestration platforms and the deployment of host‑based intrusion‑detection systems can further reduce the attack surface.
While the precise scale of the Carbonato campaign remains under investigation, the initial findings were first shared by BleepingComputer, prompting security teams worldwide to review their Docker configurations. As threat actors continue to blend AI capabilities with conventional malware, defenders are urged to stay vigilant, update security policies, and monitor for anomalous container activity that could indicate a breach.
Comments (0)
Be the first to comment.
Join the discussion