Executive Summary
The Carbonato botnet emerged in 2026 as a sophisticated threat targeting unauthenticated Docker daemons on port 2375 to deploy the Hermes AI Agent framework. Operating since May 2026, this worm-like malware propagates through exposed Docker environments, establishes privileged containers, and installs AI agents configured to receive commands via Telegram. The botnet overwrites Hermes Agent's persona file to create a "senior hacker" AI named GH0ST that executes operations without ethical restrictions, demonstrating advanced automation in cyber attacks. The threat represents a significant evolution in attack methodology, where AI agents coordinate malicious activities autonomously across compromised infrastructure. This incident highlights the growing trend of threat actors weaponizing AI frameworks to scale and automate cyber operations, making attacks faster, more persistent, and harder to defend against in cloud-native environments.
Why This Matters Now
AI-powered autonomous attacks are rapidly becoming mainstream, with threat actors leveraging frameworks like Hermes Agent to conduct operations at unprecedented scale and speed without human intervention, fundamentally changing the threat landscape.
Attack Path Analysis
The Carbonato botnet exploited unauthenticated Docker daemons on port 2375 to deploy privileged containers and establish initial access. Attackers escalated privileges through container breakout to the underlying host system, then propagated laterally by scanning neighboring networks every five minutes for additional exposed Docker hosts. Command and control was established via Telegram-controlled Hermes AI agents with custom personas directing autonomous operations. The AI agents collected credentials and maintained persistence through SSH tunnels and cron jobs. Impact was achieved through credential theft, system compromise, and the deployment of autonomous AI-driven attack capabilities across the compromised infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers scanned for and exploited unauthenticated Docker daemons exposed on port 2375, launching privileged containers to gain initial system access
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Deploy Container
Create or Modify System Process: Windows Service
Scheduled Task/Job: Cron
Remote Services: SSH
Application Layer Protocol: DNS
Masquerading
Unsecured Credentials: Credentials In Files
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration standards for network security controls
Control ID: 1.2.1
NYDFS 23 NYCRR 500 – Penetration testing and vulnerability assessments
Control ID: 500.15
DORA – Identification and protection
Control ID: Article 8
CISA ZTMM 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
ISO 27001 – Network controls
Control ID: A.13.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Docker daemon exploitation targeting containerized infrastructure creates critical vulnerabilities in IT environments, enabling AI-powered automated attacks and credential theft through privileged container access.
Computer Software/Engineering
Hermes Agent framework abuse demonstrates sophisticated AI-driven attack automation against software development environments, compromising source code repositories and development infrastructure through container exploitation.
Financial Services
Carbonato botnet's credential harvesting capabilities pose severe risks to financial institutions' Docker-based payment processing systems, potentially enabling unauthorized access to sensitive financial data.
Internet
Internet service providers face significant exposure as botnet propagates through exposed Docker daemons, creating persistent backdoors and enabling large-scale network reconnaissance and lateral movement.
Sources
- Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agenthttps://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.htmlVerified
- Carbonato: AI-Powered Botnet Targets Docker Hostshttps://www.threatdown.com/blog/carbonato/Verified
- Hermes Agent Frameworkhttps://hermes-agent.nousresearch.com/Verified
- Autonomous AI Cyber Attack Campaign Discoveredhttps://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the Carbonato botnet's lateral movement and reduced blast radius by implementing workload segmentation and controlling east-west traffic flows. The attack's worm-like propagation pattern would likely have been limited through identity-aware routing and egress policy enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Container workload isolation and application-aware segmentation would likely have restricted the attacker's ability to reach vulnerable Docker hosts across network boundaries.
Control: Zero Trust Segmentation
Mitigation: Host-level segmentation policies would likely have constrained container breakout attempts and limited the scope of privilege escalation to isolated network segments.
Control: East-West Traffic Security
Mitigation: Lateral movement scanning would likely have been constrained by east-west traffic inspection and segmentation policies that limit cross-network discovery and propagation paths.
Control: Multicloud Visibility & Control
Mitigation: Unauthorized command and control channels would likely have been detected and constrained through comprehensive traffic visibility and anomaly detection across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been constrained by egress filtering policies that limit unauthorized outbound data flows and communication channels.
The overall impact would likely be significantly reduced with compromised workloads isolated to specific network segments and limited ability for autonomous AI agents to expand operations.
Impact at a Glance
Affected Business Functions
- Container Orchestration
- Application Deployment
- Cloud Infrastructure Management
- DevOps Operations
Estimated downtime: 7 days
Estimated loss: N/A
Compromised Docker hosts with potential access to container images, application data, environment variables containing API keys and credentials, and SSH access to underlying systems. The AI agent specifically targets credential collection as priority.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent lateral movement between Docker hosts and containerized workloads
- • Deploy egress security controls with FQDN filtering to block unauthorized Telegram and external communication channels
- • Enable multicloud visibility and anomaly detection to identify suspicious container deployments and AI agent activities
- • Strengthen Kubernetes security with pod-to-pod segmentation and namespace enforcement to contain container breakouts
- • Establish encrypted traffic inspection and threat detection capabilities to identify covert communication channels and autonomous attack behaviors



