Back to Feed
MalwareSep 28, 2026

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

Carbonato botnet deploys Hermes Agent AI framework on compromised Docker hosts to steal API keys via Telegram.

Summary

The Carbonato botnet has been observed leveraging the open source Hermes Agent AI framework to compromise Docker hosts and execute remote commands through Telegram. The malware targets exposed Docker instances to steal AI API keys and credentials, representing a convergence of botnet tactics with AI-powered automation. This campaign highlights the emerging risk of threat actors weaponizing legitimate AI frameworks against cloud infrastructure.

Indicators of Compromise

  • malware — Carbonato
  • malware — Hermes Agent

Entities

Carbonato operators (threat_actor)Docker (technology)Hermes Agent AI framework (technology)Telegram (technology)