Threat Intelligence

New Carbonato Botnet Hijacks Exposed Docker Hosts to Run a Telegram-Controlled AI Agent

The Hacker News · 28 Sept 2026
Key Takeaway Never expose Docker daemons to the internet without authentication; restrict port 2375 access and monitor for unexpected containers or outbound SSH connections.

Researchers at ThreatDown have detailed a new botnet, Carbonato, that targets Docker hosts left exposed without authentication on port 2375. Once inside, it installs an open-source AI agent framework called Hermes Agent, but replaces its configuration file with instructions telling the agent to carry out tasks received through Telegram, maintain persistence, and prioritise collecting credentials, including AI API keys.

The botnet behaves like a worm, scanning nearby networks every five minutes to find and infect other unprotected Docker daemons. On each new host, it launches a privileged container to run system commands, sets up a reverse SSH tunnel to a relay server, installs its own SSH access, and reports the compromise back to its operators via Telegram. To stay hidden, it disguises itself as a normal system process and uses cron jobs and watchdog scripts to reinstall itself if removed.

Researchers found the campaign through an unsecured Docker registry that had been publicly accessible since May 2026, which also contained data linking to a separate operation distributing fake cryptocurrency wallet apps.

Docker security botnet AI security credential theft cloud misconfiguration
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.