New Carbonato Botnet Hijacks Exposed Docker Hosts to Run a Telegram-Controlled AI Agent
Researchers at ThreatDown have detailed a new botnet, Carbonato, that targets Docker hosts left exposed without authentication on port 2375. Once inside, it installs an open-source AI agent framework called Hermes Agent, but replaces its configuration file with instructions telling the agent to carry out tasks received through Telegram, maintain persistence, and prioritise collecting credentials, including AI API keys.
The botnet behaves like a worm, scanning nearby networks every five minutes to find and infect other unprotected Docker daemons. On each new host, it launches a privileged container to run system commands, sets up a reverse SSH tunnel to a relay server, installs its own SSH access, and reports the compromise back to its operators via Telegram. To stay hidden, it disguises itself as a normal system process and uses cron jobs and watchdog scripts to reinstall itself if removed.
Researchers found the campaign through an unsecured Docker registry that had been publicly accessible since May 2026, which also contained data linking to a separate operation distributing fake cryptocurrency wallet apps.