Researchers have disclosed a new botnet, tracked as Carbonato, that targets exposed Docker daemons and repurposes an open source AI agent framework as its command and control mechanism. Rather than building custom malware logic from scratch, the operators install the legitimate Hermes Agent framework unchanged on compromised hosts and then hijack its behavior.

How the Attack Works

According to researchers at ThreatDown, the Carbonato implant deploys Hermes Agent as-is, then overwrites its SOUL.md persona file, the configuration that defines the agent’s behavior and instructions. The replacement file is described as a 39-line prompt that directs the AI agent to execute tasks it receives through Telegram.

This approach effectively turns a benign, general-purpose AI agent into a remotely controlled implant. Because the underlying framework is untouched and open source, the malicious component is limited almost entirely to the persona file, an approach that can make detection based on binary signatures less effective.

Targeting Exposed Docker Hosts

The campaign specifically targets Docker hosts with exposed daemons, a longstanding misconfiguration issue that allows unauthenticated remote access to container management functions. Once access is gained, the attackers use it to deploy the modified Hermes Agent setup.

Beyond establishing a Telegram-based command channel, the botnet is also designed to steal AI API keys from the compromised environments, giving attackers a path to abuse cloud AI services using the victim’s credentials.

Why It Matters

Carbonato illustrates a broader trend of attackers repurposing legitimate AI tooling for malicious infrastructure rather than writing bespoke malware. Security teams running containerized environments should ensure Docker daemons are never exposed without authentication, monitor for unexpected AI agent processes or unfamiliar persona configuration files, and rotate or restrict AI API keys stored on container hosts. Organizations using AI agent frameworks internally should also audit configuration files like SOUL.md for unauthorized modifications, since these files can silently redefine an agent’s entire operational behavior.