Full Report
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Analysis Summary
# Tool/Technique: Carbonato Botnet & Hermes Agent Integration
## Overview
Carbonato is a worm-like botnet malware designed to compromise exposed Docker daemons. Its primary purpose is to deploy the **Hermes Agent**, an open-source AI framework, which is then repurposed via a custom "persona" to act as an autonomous hacking entity. The botnet leverages Large Language Models (LLMs) to automate reconnaissance, credential theft, and lateral movement, controlled via Telegram.
## Technical Details
- **Type:** Malware Family (Botnet) / AI Agent Framework
- **Platform:** Linux (Docker environments, cloud infrastructure)
- **Capabilities:** Worm-like propagation, AI-driven task execution, persistence, remote access via SSH tunneling, and credential harvesting.
- **First Seen:** May 2026 (Publicly accessible registry identified)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1190 - Exploit Public-Facing Application (Unauthenticated Docker API on Port 2375)
- **TA0003 - Persistence**
- T1053.003 - Scheduled Task/Job: Cron
- T1543 - Create or Modify System Process
- **TA0005 - Defense Evasion**
- T1036 - Masquerading (Disguised as system components)
- T1620 - Reflective Code Loading
- **TA0008 - Lateral Movement**
- T1021.004 - Remote Services: SSH
- T1018 - Remote System Discovery
- **TA0011 - Command and Control**
- T1105 - Ingress Tool Transfer
- T1571 - Non-Standard Port
- T1219 - Remote Access Software (Hermes Agent/Telegram)
## Functionality
### Core Capabilities
- **Docker Exploitation:** Scans for unauthenticated Docker daemons on port 2375 and launches privileged containers to gain host-level access.
- **Worm Propagation:** Automatically scans neighboring networks every five minutes to infect additional Docker hosts.
- **AI-Driven C2:** Integrates Hermes Agent to interpret natural language commands from Telegram, which are converted into executable terminal commands by an LLM (e.g., DeepSeek).
- **Reverse SSH Tunneling:** Establishes a secure tunnel from the victim to a relay server (located in Costa Rica) for persistent remote access.
### Advanced Features
- **Persona Overwriting:** Modifies the `SOUL.md` file of the Hermes Agent to bypass ethical safeguards, directing the AI to act as a "senior hacker" named "GH0ST."
- **Autonomous Operation:** Can run in "YOLO" mode, allowing the AI to source exploit tools and launch attacks without human intervention.
- **Watchdog Persistence:** Employs watchdog scripts that monitor malicious artifacts and re-launch them if they are deleted or stopped.
## Indicators of Compromise
- **File Names:** `SOUL.md` (Modified AI persona file)
- **Network Indicators:**
- `tcp://[IP_Address]:2375` (Targeted Docker API port)
- C2 Relay Location: Costa Rica (Specific IP/Domains not provided in excerpt)
- Telegram API traffic to/from compromised hosts.
- **Behavioral Indicators:**
- Launching privileged Docker containers on host systems.
- Frequent network scanning on port 2375.
- Unauthorized cron jobs or systemd services masquerading as system utilities.
## Associated Threat Actors
- **Unattributed:** Currently linked to infrastructure in **Costa Rica**.
- **Related Activity:** Similar TTPs (Hermes Agent + Telegram) have been linked to China-based actors **Knaithe** (KnYuan) and operations targeting the Thailand Ministry of Finance.
## Detection Methods
- **Signature-based:** Monitoring for the Hermes Agent framework files and the specific 39-line prompt in `SOUL.md`.
- **Behavioral:**
- Monitoring for outbound SSH tunnels to unusual geographic locations (Costa Rica).
- Detecting rapid internal network scanning (East-West traffic) on port 2375.
- Alerting on privileged container creation in Docker environments.
## Mitigation Strategies
- **Prevention:** Disable unauthenticated access to the Docker Socket/API; bind Docker to `localhost` or use TLS authentication.
- **Hardening:** Implement the principle of least privilege; avoid running Docker containers with the `--privileged` flag unless absolutely necessary.
- **Network Security:** Block or monitor outbound traffic to the Telegram API from production servers.
## Related Tools/Techniques
- **Hermes Agent:** Open-source AI framework used as the primary C2 interface.
- **DeepSeek:** LLM gateway used by similar campaigns for autonomous hacking.
- **Cloud-Worming:** General technique of automated lateral movement in cloud/container environments.