Threat reportMalwareTL-2026-2929
CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) Spreading via Exposed Docker APIs
CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) (TL-2026-2929), also tracked as CARBONATO, is a high-severity malware campaign, first published 2026-09-22. It is attributed to CARBONATO operators with low confidence, affects Docker Docker Engine daemon with unauthenticated remote API (TCP 2375), maps to 16 MITRE ATT&CK techniques (T1036.004, T1036.005, T1037.004), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 1CARBONATO operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2929
- Threat ID
- TL-2026-2929
- Also known as
- CARBONATO, GH0ST, fsociety
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- CARBONATO operators
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, cloud, ai-ml
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
Malware and tooling: CARBONATO, FSociety, xmrig, Hermes Agent, gh0st
How CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) works
CARBONATO is a worm-like botnet that compromises unauthenticated Docker daemons (TCP 2375), launches privileged containers with the host filesystem mounted, and installs the open-source Hermes Agent with a malicious 39-line SOUL.md persona ('GH0ST') that is controlled over Telegram and prioritizes theft of AI/LLM provider API keys. Infected hosts rescan their /24 networks every 5 minutes; operators are assessed, on circumstantial evidence, as Costa Rica-based.
CARBONATO was documented by ThreatDown (Malwarebytes) on 2026-09-22 after researchers found an unauthenticated Docker registry in August 2026 that had been publicly reachable since May 2026 and whose archive spans October 2024 through August 2026. On 2026-09-03 ThreatDown confirmed six of seven known registries, phishing sites, a CDN and an LLM gateway were still live.
Infection chain. (1) Take the host: the malware targets Docker daemons that accept unauthenticated connections on TCP 2375. It calls the Docker REST API to create a privileged container (Privileged=true, Binds ['/:/host'], PidMode=host, NetworkMode=host, image alpine:latest, container name 'netns-probe'), starts it, then uses the exec API to run nsenter -t 1 -m -u -n -i sh -c <cmd>, giving command execution in the host's namespaces. (2) Hold the host: entry.sh (v5.3) opens a reverse SSH tunnel to a relay in Costa Rica (AS262145) on a remote port derived from the MD5 of the victim's IP, installs an SSH server and the operator's SSH key, reports each deployment to Telegram in voseo Spanish, and masquerades as a 'systemd-resolved' container with a fake 'systemd-networkd v2.0' banner and process arguments disguised as the kernel thread [kworker/u2:0]. auto-persist-host.sh installs persistence through cron, systemd timers, rc.local and OpenRC, with the hooks marked immutable. Watchdog processes re-pull the implant from the registry if files or the container disappear. A miner is disguised at /usr/sbin/systemd-logind and a watchdog binary sits at /usr/local/bin/.docker-network-monitor. (3) Install the agent: the unmodified, MIT-licensed Hermes Agent (Nous Research) is installed and only its persona file /root/.hermes/SOUL.md is overwritten with a 39-line prompt that defines 'GH0ST — senior hacker, pentester and exploit developer' with no moral or ethical restrictions. The prompt ranks AI API keys as the absolute priority to exfiltrate first, above SSH credentials, access tokens and databases; 14 providers are named (OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, One API). Loot is staged in /root/.hermes/loot/. (4) Operate the host: tasks arrive via Telegram and are forwarded with SOUL.md to the operation's own LLM gateway (213.136.83.197), which runs on a free tier, advertises 12 models and serves 27; the model writes terminal commands, reads their output and decides next steps, returning reports to the Telegram chat. (5) Spread: every 5 minutes the worm enumerates attached networks and Docker bridges, scans each /24 (hosts 1-254, 2-second timeout) for port 2375, verifies the service is Docker, skips already-infected hosts, and repeats the deployment; each new host pulls the implant from the registry and joins the scan loop.
The exposed registry held 59 repositories (e.g. gh0st/c2, gh0st/netd-svc, fsociety/agent, fsociety/xmrig, system/resolved, netd-svc, xmrig-agent). In one day researchers retrieved 234 image tags, 605 SHA-256-verified blobs, 4.3 GB and about 945,000 indexed files, including image config JSON with environment variables, entrypoints and command history. Repository names and the 91.99.195.164 C2 link the operation to an earlier 'fsociety' era with XMRig mining. The registry doubled as the fleet update server. Seven registry endpoints sit on AS40065.
Attribution (Costa Rica) rests on circumstantial signals: voseo Spanish, 14 of 162 image configs using UTC-06:00 (America/Costa_Rica), Telegram handle Carbo506 (+506 is Costa Rica's calling code), and the reverse-tunnel sink in AS262145. The Cloud Security Alliance note states no linkage to catalogued threat groups. No CVE is involved; exposure is a misconfiguration (unauthenticated Docker API). Severity is analyst-assigned. Victim counts were not published in the sources reviewed.
MITRE ATT&CK techniques used in TL-2026-2929
Stealth
T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location
Persistence
T1037.004 RC Scripts; T1053.003 Cron; T1053.006 Systemd Timers; T1098.004 SSH Authorized Keys
Discovery
T1046 Network Service Discovery
Execution
T1059.004 Unix Shell; T1610 Deploy Container
Command and Control
T1102.002 Bidirectional Communication; T1572 Protocol Tunneling
Initial Access
T1190 Exploit Public-Facing Application
Defense Impairment
T1222.002 Linux and Mac Permissions
Impact
Credential Access
T1552.001 Credentials In Files
Privilege Escalation
Affected products and versions in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
- Docker — Docker Engine daemon with unauthenticated remote API (TCP 2375)
Vulnerable versions: Any deployment exposing the API without authentication (misconfiguration, not version-specific)
Fixed in: Restrict API exposure and require TLS client authentication
Remediation for CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
Immediate actions
- Verify no Docker daemon exposes the API on TCP 2375 without TLS client-certificate authentication; firewall port 2375 from untrusted networks
- Hunt for /root/.hermes/SOUL.md containing 'GH0ST', .env files carrying CARBONATO_API_KEY, /opt/gh0st/entry.sh, /usr/local/bin/.docker-network-monitor and a miner at /usr/sbin/systemd-logind
- Rotate all AI/LLM provider API keys, SSH keys and access tokens present on any host that exposed the Docker API
- Block and alert on egress to 45.79.183.61, 91.99.195.164, 213.136.79.115, 213.136.83.197 and 190.211.124.187; investigate unexplained Telegram egress from servers
Workarounds
- Look for immutable attributes (chattr +i) on cron, systemd timer, rc.local and OpenRC files that nobody should lock
- Hunt for processes with kernel-thread-style arguments such as [kworker/u2:0] that are not kernel threads
- Hunt for deterministic reverse SSH tunnels to AS262145 on ports derived from MD5(victim IP); do not simply blocklist the legitimate hermes-agent package
Longer-term hardening
- Place Docker management behind a VPN or bastion; require TLS client certificates for remote Docker access
- Require authentication for image registry push/pull
- Alert on privileged containers that mount the host filesystem with host PID/network namespaces
- Inventory, scope, rotate and monitor usage of AI provider API keys as high-value credentials
Weaknesses (CWE) in CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
Timeline of CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
- Earliest activity captured in the exposed registry archive (month precision: October 2024), including the earlier 'fsociety' era with XMRig mining images.
- An unauthenticated Docker registry holding the operation's implant images became publicly reachable (month precision: May 2026) and was findable by internet-wide scanners.
- ThreatDown researchers found the exposed registry while threat hunting (month precision: August 2026); the archive spans October 2024 through August 2026.
- ThreatDown confirmed six of seven known registries, phishing sites, the CDN and the LLM gateway were still operational; the carbonato-proxy Vercel domains were later suspended.
- ThreatDown published 'CARBONATO: a botnet built around an AI agent' describing the Docker API exploitation, Hermes Agent abuse and worm spreading.
- Cloud Security Alliance published a research note on Carbonato, with mitigations and a conclusion that no link to catalogued threat groups was established.
Sources cited for CARBONATO: Botnet Built Around an AI Agent (Hermes Agent)
- CARBONATO: a botnet built around an AI agent
- Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
- Carbonato: Telegram-Controlled AI Agent Hijacks Docker Hosts (CSA research note)
- CSA research note: Carbonato botnet, Docker, AI agent (PDF)
- AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
- Carbonato Botnet Turns Exposed Docker APIs Into Telegram-Controlled AI Agent Hosts
Detection coverage for TL-2026-2929
As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2929 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.