Part of a story covered by 6 sources: “Carbonato Botnet Hijacks Exposed Docker Hosts Using Hermes” — merged summary and timeline →
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
AI summary · grok-4.7
Carbonato installs Hermes Agent on hacked Docker hosts to run Telegram commands and steal AI API keys.
The Carbonato botnet places the open-source Hermes Agent AI framework on compromised Docker hosts. Operators use the agent to execute commands over Telegram and to steal AI API keys from exposed hosts. The report describes active abuse of container infrastructure rather than a named vulnerability or patch.
- Carbonato botnet compromises exposed Docker hosts.
- It deploys the open-source Hermes Agent framework.
- Attackers execute commands through Telegram.
- The botnet steals AI API keys from those hosts.
Full article
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.