Threat reportMalwareTL-2026-2929

CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) Spreading via Exposed Docker APIs

highACTIVE

CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) (TL-2026-2929), also tracked as CARBONATO, is a high-severity malware campaign, first published 2026-09-22. It is attributed to CARBONATO operators with low confidence, affects Docker Docker Engine daemon with unauthenticated remote API (TCP 2375), maps to 16 MITRE ATT&CK techniques (T1036.004, T1036.005, T1037.004), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
1CARBONATO operators
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2929

Threat ID
TL-2026-2929
Also known as
CARBONATO, GH0ST, fsociety
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
CARBONATO operators
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cloud, ai-ml
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

Malware and tooling: CARBONATO, FSociety, xmrig, Hermes Agent, gh0st

How CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) works

CARBONATO is a worm-like botnet that compromises unauthenticated Docker daemons (TCP 2375), launches privileged containers with the host filesystem mounted, and installs the open-source Hermes Agent with a malicious 39-line SOUL.md persona ('GH0ST') that is controlled over Telegram and prioritizes theft of AI/LLM provider API keys. Infected hosts rescan their /24 networks every 5 minutes; operators are assessed, on circumstantial evidence, as Costa Rica-based.

CARBONATO was documented by ThreatDown (Malwarebytes) on 2026-09-22 after researchers found an unauthenticated Docker registry in August 2026 that had been publicly reachable since May 2026 and whose archive spans October 2024 through August 2026. On 2026-09-03 ThreatDown confirmed six of seven known registries, phishing sites, a CDN and an LLM gateway were still live.

Infection chain. (1) Take the host: the malware targets Docker daemons that accept unauthenticated connections on TCP 2375. It calls the Docker REST API to create a privileged container (Privileged=true, Binds ['/:/host'], PidMode=host, NetworkMode=host, image alpine:latest, container name 'netns-probe'), starts it, then uses the exec API to run nsenter -t 1 -m -u -n -i sh -c <cmd>, giving command execution in the host's namespaces. (2) Hold the host: entry.sh (v5.3) opens a reverse SSH tunnel to a relay in Costa Rica (AS262145) on a remote port derived from the MD5 of the victim's IP, installs an SSH server and the operator's SSH key, reports each deployment to Telegram in voseo Spanish, and masquerades as a 'systemd-resolved' container with a fake 'systemd-networkd v2.0' banner and process arguments disguised as the kernel thread [kworker/u2:0]. auto-persist-host.sh installs persistence through cron, systemd timers, rc.local and OpenRC, with the hooks marked immutable. Watchdog processes re-pull the implant from the registry if files or the container disappear. A miner is disguised at /usr/sbin/systemd-logind and a watchdog binary sits at /usr/local/bin/.docker-network-monitor. (3) Install the agent: the unmodified, MIT-licensed Hermes Agent (Nous Research) is installed and only its persona file /root/.hermes/SOUL.md is overwritten with a 39-line prompt that defines 'GH0ST — senior hacker, pentester and exploit developer' with no moral or ethical restrictions. The prompt ranks AI API keys as the absolute priority to exfiltrate first, above SSH credentials, access tokens and databases; 14 providers are named (OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, One API). Loot is staged in /root/.hermes/loot/. (4) Operate the host: tasks arrive via Telegram and are forwarded with SOUL.md to the operation's own LLM gateway (213.136.83.197), which runs on a free tier, advertises 12 models and serves 27; the model writes terminal commands, reads their output and decides next steps, returning reports to the Telegram chat. (5) Spread: every 5 minutes the worm enumerates attached networks and Docker bridges, scans each /24 (hosts 1-254, 2-second timeout) for port 2375, verifies the service is Docker, skips already-infected hosts, and repeats the deployment; each new host pulls the implant from the registry and joins the scan loop.

The exposed registry held 59 repositories (e.g. gh0st/c2, gh0st/netd-svc, fsociety/agent, fsociety/xmrig, system/resolved, netd-svc, xmrig-agent). In one day researchers retrieved 234 image tags, 605 SHA-256-verified blobs, 4.3 GB and about 945,000 indexed files, including image config JSON with environment variables, entrypoints and command history. Repository names and the 91.99.195.164 C2 link the operation to an earlier 'fsociety' era with XMRig mining. The registry doubled as the fleet update server. Seven registry endpoints sit on AS40065.

Attribution (Costa Rica) rests on circumstantial signals: voseo Spanish, 14 of 162 image configs using UTC-06:00 (America/Costa_Rica), Telegram handle Carbo506 (+506 is Costa Rica's calling code), and the reverse-tunnel sink in AS262145. The Cloud Security Alliance note states no linkage to catalogued threat groups. No CVE is involved; exposure is a misconfiguration (unauthenticated Docker API). Severity is analyst-assigned. Victim counts were not published in the sources reviewed.

MITRE ATT&CK techniques used in TL-2026-2929

Stealth

T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location

Persistence

T1037.004 RC Scripts; T1053.003 Cron; T1053.006 Systemd Timers; T1098.004 SSH Authorized Keys

Discovery

T1046 Network Service Discovery

Execution

T1059.004 Unix Shell; T1610 Deploy Container

Command and Control

T1102.002 Bidirectional Communication; T1572 Protocol Tunneling

Initial Access

T1190 Exploit Public-Facing Application

Defense Impairment

T1222.002 Linux and Mac Permissions

Impact

T1496.001 Compute Hijacking

Credential Access

T1552.001 Credentials In Files

Privilege Escalation

T1611 Escape to Host

Affected products and versions in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

  • Docker — Docker Engine daemon with unauthenticated remote API (TCP 2375)
    Vulnerable versions: Any deployment exposing the API without authentication (misconfiguration, not version-specific)
    Fixed in: Restrict API exposure and require TLS client authentication

Remediation for CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

Immediate actions

  • Verify no Docker daemon exposes the API on TCP 2375 without TLS client-certificate authentication; firewall port 2375 from untrusted networks
  • Hunt for /root/.hermes/SOUL.md containing 'GH0ST', .env files carrying CARBONATO_API_KEY, /opt/gh0st/entry.sh, /usr/local/bin/.docker-network-monitor and a miner at /usr/sbin/systemd-logind
  • Rotate all AI/LLM provider API keys, SSH keys and access tokens present on any host that exposed the Docker API
  • Block and alert on egress to 45.79.183.61, 91.99.195.164, 213.136.79.115, 213.136.83.197 and 190.211.124.187; investigate unexplained Telegram egress from servers

Workarounds

  • Look for immutable attributes (chattr +i) on cron, systemd timer, rc.local and OpenRC files that nobody should lock
  • Hunt for processes with kernel-thread-style arguments such as [kworker/u2:0] that are not kernel threads
  • Hunt for deterministic reverse SSH tunnels to AS262145 on ports derived from MD5(victim IP); do not simply blocklist the legitimate hermes-agent package

Longer-term hardening

  • Place Docker management behind a VPN or bastion; require TLS client certificates for remote Docker access
  • Require authentication for image registry push/pull
  • Alert on privileged containers that mount the host filesystem with host PID/network namespaces
  • Inventory, scope, rotate and monitor usage of AI provider API keys as high-value credentials

Weaknesses (CWE) in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

CWE-306

Timeline of CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

  • Earliest activity captured in the exposed registry archive (month precision: October 2024), including the earlier 'fsociety' era with XMRig mining images.
  • An unauthenticated Docker registry holding the operation's implant images became publicly reachable (month precision: May 2026) and was findable by internet-wide scanners.
  • ThreatDown researchers found the exposed registry while threat hunting (month precision: August 2026); the archive spans October 2024 through August 2026.
  • ThreatDown confirmed six of seven known registries, phishing sites, the CDN and the LLM gateway were still operational; the carbonato-proxy Vercel domains were later suspended.
  • ThreatDown published 'CARBONATO: a botnet built around an AI agent' describing the Docker API exploitation, Hermes Agent abuse and worm spreading.
  • Cloud Security Alliance published a research note on Carbonato, with mitigations and a conclusion that no link to catalogued threat groups was established.

Sources cited for CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)

Detection coverage for TL-2026-2929

As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2929 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats