Military & Security

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

· September 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

What happened

A new botnet malware named Carbonato is actively compromising Docker hosts by exploiting exposed Docker daemons. Once inside, it deploys an open-source AI agent framework called Hermes Agent. The interesting twist is the botnet does not alter the AI framework itself but instead overwrites the SOUL.md persona file that directs the agent’s behavior. This persona file contains just 39 lines of prompt code instructing the AI to carry out tasks it receives via Telegram messages controlled by the attackers.

The risk

Carbonato specifically targets Docker hosts with misconfigured or exposed remote APIs, a common but avoidable security lapse. The infection chain leverages this gap to introduce an AI-powered agent capable of executing arbitrary commands on compromised systems. This approach raises the stakes for container operators who often assume their workloads run in isolated environments but may have leave open backdoors. By using Telegram as a command-and-control channel, attackers gain resilience and stealth, making response and remediation more complex.

Why it matters

Open-source AI frameworks like Hermes Agent were never built to serve as backdoors. Abuse of these tools for remote control and automation shifts the enterprise risk calculus for AI adoption and integration into operational workflows. Operators of Docker environments face immediate pressure to secure Docker daemons by disabling remote APIs or enforcing strict network controls. Businesses relying on containerization could see increased operational risk, forcing investments in better monitoring and intrusion detection where AI agents could silently run commands.

Who should pay attention

Developers, DevOps teams, and security professionals managing container infrastructure must prioritize hardening Docker hosts. Founders and operators of AI-driven automation projects should also be aware that open-source AI agents can be weaponized. Cybersecurity teams should update threat models to include AI-based malware use through common developer tools. Investors examining AI cybersecurity startups should note growing use of AI frameworks within attack toolkits as a signal of evolving threat sophistication.

What to watch next

Monitor how defenders respond with new detection methods tailored to AI agent-driven malware. Look for updates from container orchestration platforms tightening default API exposure. Track whether attackers continue expanding AI agent control channels beyond Telegram. Watch for community patches or changes to Hermes Agent or similar AI frameworks to mitigate misuse risks. Security researchers will likely surface additional Carbonato variants or analogous botnets targeting other AI tools and environments.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.