The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The Carbonato botnet emerged in 2026 as a sophisticated threat targeting unauthenticated Docker daemons on port 2375 to deploy the Hermes AI Agent framework. Operating since May 2026, this worm-like malware propagates through exposed Docker environments, establishes privileged containers, and installs AI agents configured to receive commands via Telegram. The botnet overwrites Hermes Agent's persona file to create a "senior hacker" AI named GH0ST that executes operations without ethical restrictions, demonstrating advanced automation in cyber attacks. The threat represents a significant evolution in attack methodology, where AI agents coordinate malicious activities autonomously across compromised infrastructure. This incident highlights the growing trend of threat actors weaponizing AI frameworks to scale and automate cyber operations, making attacks faster, more persistent, and harder to defend against in cloud-native environments.

Why This Matters Now

AI-powered autonomous attacks are rapidly becoming mainstream, with threat actors leveraging frameworks like Hermes Agent to conduct operations at unprecedented scale and speed without human intervention, fundamentally changing the threat landscape.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Carbonato targets unauthenticated Docker daemons exposed on port 2375, launches privileged containers, and spreads through network scanning to propagate to additional vulnerable hosts.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the Carbonato botnet's lateral movement and reduced blast radius by implementing workload segmentation and controlling east-west traffic flows. The attack's worm-like propagation pattern would likely have been limited through identity-aware routing and egress policy enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Container workload isolation and application-aware segmentation would likely have restricted the attacker's ability to reach vulnerable Docker hosts across network boundaries.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Host-level segmentation policies would likely have constrained container breakout attempts and limited the scope of privilege escalation to isolated network segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement scanning would likely have been constrained by east-west traffic inspection and segmentation policies that limit cross-network discovery and propagation paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Unauthorized command and control channels would likely have been detected and constrained through comprehensive traffic visibility and anomaly detection across multicloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely have been constrained by egress filtering policies that limit unauthorized outbound data flows and communication channels.

Impact (Mitigations)

The overall impact would likely be significantly reduced with compromised workloads isolated to specific network segments and limited ability for autonomous AI agents to expand operations.

Impact at a Glance

Affected Business Functions

  • Container Orchestration
  • Application Deployment
  • Cloud Infrastructure Management
  • DevOps Operations
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Compromised Docker hosts with potential access to container images, application data, environment variables containing API keys and credentials, and SSH access to underlying systems. The AI agent specifically targets credential collection as priority.

Recommended Actions

  • • Implement Zero Trust segmentation to prevent lateral movement between Docker hosts and containerized workloads
  • • Deploy egress security controls with FQDN filtering to block unauthorized Telegram and external communication channels
  • • Enable multicloud visibility and anomaly detection to identify suspicious container deployments and AI agent activities
  • • Strengthen Kubernetes security with pod-to-pod segmentation and namespace enforcement to contain container breakouts
  • • Establish encrypted traffic inspection and threat detection capabilities to identify covert communication channels and autonomous attack behaviors

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image