Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
CARBONATO botnet hijacks exposed Docker servers and uses Hermes Agent for operator control.
ThreatDown researchers documented CARBONATO, a botnet that compromises Docker daemons left unauthenticated on TCP port 2375. Implants create a privileged container with the host filesystem mounted, open a reverse SSH tunnel, hide behind legitimate-looking process names, and persist via cron, systemd timers, and boot scripts. Attackers install Nous Research's Hermes Agent largely unchanged, replacing SOUL.md with a GH0ST persona that accepts Telegram tasks and prioritizes stealing AI API keys. A US-hosted registry leaked fleet images and attacker credentials; six of seven known registries were still online on September 3, 2026.
- CARBONATO targets unauthenticated Docker APIs on TCP port 2375.
- A privileged container mounts the host filesystem and escapes to the host.
- Persistence uses cron, systemd timers, boot scripts, and immutable files.
- Hermes Agent runs a GH0ST persona that takes tasks over Telegram.
- The persona prioritizes theft of API keys from major AI providers.
Full article893 words · extracted from gbhackers.com · click to collapse
A Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer.
The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations.
The investigation began in August 2026 after researchers identified a publicly accessible Docker Registry hosted on a US-based server.
The registry had reportedly been exposed since May and allowed unauthenticated requests.
During one day of passive collection, researchers recovered 59 repositories, 234 image tags, 605 SHA-256-verified blobs and roughly 4.3 GB of container-image data spanning October 2024 through August 2026.
The leaked archive documented two apparently linked operations: a counterfeit cryptocurrency-wallet distribution network and a Docker botnet operation.
Registry image metadata, environment variables, entrypoints and command histories exposed infrastructure details, including command-and-control addresses, Telegram bot tokens and credentials associated with the attackers’ LLM gateway.
In effect, the registry served both as a forensic goldmine and as the malware fleet’s update mechanism.
Docker warns that insecure remote daemon access can enable remote users to gain root-level access on the host; unencrypted TCP access on port 2375 is specifically discouraged.
The malware abuses the daemon to create a privileged container with the host filesystem mounted and access to host process and network namespaces.
From that container, it executes commands in the host context, turning an exposed Docker service into a direct path to full server compromise.
After initial access, the implant establishes a reverse SSH tunnel to infrastructure associated with the operation and installs an SSH key for continued access.
It attempts to conceal itself by using container names and process arguments that resemble legitimate Linux components, including systemd-resolved and kernel-worker-style process names.

The malware also creates persistence through cron jobs, systemd timers, rc.local and OpenRC mechanisms, then marks selected files immutable to complicate removal.
ThreatDown researchers uncovered CARBONATO, exploits Docker Remote APIs that accept unauthenticated connections, typically on port 2375.
Docker Server Hijacking
A watchdog component monitors the deployment and re-pulls the implant from the exposed registry when files or containers are removed.
This design means remediation cannot stop at deleting a suspicious container: defenders must identify persistence hooks, revoke remote access, inspect host modifications and eliminate the attacker-controlled image source.
The most notable component is the installation of Hermes Agent, an MIT-licensed open-source framework developed by Nous Research.
Hermes Agent is designed as a self-improving AI agent with persistent context and terminal-oriented capabilities.
Researchers said the attackers did not substantially modify the framework itself. Instead, they overwrite its SOUL.md persona file with a 39-line malicious instruction set before launching it.
The altered persona, named GH0ST, instructs the agent to maintain persistence, receive tasks through Telegram and execute operator-directed actions on compromised systems.
It prioritizes theft of AI API keys over SSH credentials, access tokens and databases, naming providers including OpenAI, Anthropic, Google, OpenRouter, Together, Groq, Mistral, Cohere and others.
This reflects the rising operational value of AI credentials, which can be abused for costly inference, access to private models and datasets, or further automated intrusion activity.

The AI component does not drive propagation. CARBONATO’s surrounding shell scripts scan connected host and Docker-bridge networks every five minutes for additional port 2375 endpoints, validate reachable Docker services and deploy the implant to newly found systems.
Hermes Agent instead functions as an operator interface after compromise: Telegram-delivered objectives are passed with the malicious persona to an LLM gateway, which generates commands, evaluates output and continues the task loop on the victim host.
Researchers observed that six of seven known registries, the phishing infrastructure, the content-delivery network and the LLM gateway remained online as of September 3.
Linguistic clues in deployment messages, timezone settings, a Telegram handle and reverse-tunnel infrastructure suggest a possible Costa Rica nexus, although the evidence is not sufficient for definitive attribution.
Organizations should immediately remove public access to Docker’s unauthenticated API, bind Docker only to local Unix sockets or protected interfaces, and use TLS with client authentication for any necessary remote administration.
Docker’s Registry V2 authentication model supports authorization workflows that return 401 Unauthorized challenges and bearer-token requirements when a registry is correctly protected.
Defenders should hunt for /root/.hermes/SOUL.md containing references to GH0ST, suspicious Telegram egress from servers, immutable cron or systemd files, unexpected privileged containers, /usr/local/bin/.docker-network-monitor, and processes impersonating [kworker/u2:0].
AI API keys should be inventoried, rotated where exposure is possible and monitored for anomalous use.
Indicators of compromise
| Type | Indicator | Notes |
|---|---|---|
| Network | 45[.]79[.]183[.]61 | C2 hub (Linode) |
| Network | 91[.]99[.]195[.]164 | fsociety-era C2 (Hetzner) |
| Network | 213[.]136[.]79[.]115 | Beacon / reverse shell (Contabo,:8080 and :4444) |
| Network | 213[.]136[.]83[.]197 | LLM gateway (Contabo), live |
| Network | 190[.]211[.]124[.]187 | Reverse-tunnel sink (AS262145,Costa Rica) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.