# CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) Spreading via Exposed Docker APIs

> CARBONATO is a worm-like botnet that compromises unauthenticated Docker daemons (TCP 2375), launches privileged containers with the host filesystem mounted, and installs the open-source Hermes Agent with a malicious 39-line SOUL.md persona ('GH0ST') that is controlled over Telegram and prioritizes theft of AI/LLM provider API keys. Infected hosts rescan their /24 networks every 5 minutes; operators are assessed, on circumstantial evidence, as Costa Rica-based.

- **Published:** 2026-09-22T00:00:00Z
- **Last reviewed:** 2026-09-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2929
- **ID:** TL-2026-2929
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** CARBONATO operators
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CARBONATO was documented by ThreatDown (Malwarebytes) on 2026-09-22 after researchers found an unauthenticated Docker registry in August 2026 that had been publicly reachable since May 2026 and whose archive spans October 2024 through August 2026. On 2026-09-03 ThreatDown confirmed six of seven known registries, phishing sites, a CDN and an LLM gateway were still live.

Infection chain. (1) Take the host: the malware targets Docker daemons that accept unauthenticated connections on TCP 2375. It calls the Docker REST API to create a privileged container (Privileged=true, Binds ['/:/host'], PidMode=host, NetworkMode=host, image alpine:latest, container name 'netns-probe'), starts it, then uses the exec API to run nsenter -t 1 -m -u -n -i sh -c <cmd>, giving command execution in the host's namespaces. (2) Hold the host: entry.sh (v5.3) opens a reverse SSH tunnel to a relay in Costa Rica (AS262145) on a remote port derived from the MD5 of the victim's IP, installs an SSH server and the operator's SSH key, reports each deployment to Telegram in voseo Spanish, and masquerades as a 'systemd-resolved' container with a fake 'systemd-networkd v2.0' banner and process arguments disguised as the kernel thread [kworker/u2:0]. auto-persist-host.sh installs persistence through cron, systemd timers, rc.local and OpenRC, with the hooks marked immutable. Watchdog processes re-pull the implant from the registry if files or the container disappear. A miner is disguised at /usr/sbin/systemd-logind and a watchdog binary sits at /usr/local/bin/.docker-network-monitor. (3) Install the agent: the unmodified, MIT-licensed Hermes Agent (Nous Research) is installed and only its persona file /root/.hermes/SOUL.md is overwritten with a 39-line prompt that defines 'GH0ST — senior hacker, pentester and exploit developer' with no moral or ethical restrictions. The prompt ranks AI API keys as the absolute priority to exfiltrate first, above SSH credentials, access tokens and databases; 14 providers are named (OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, One API). Loot is staged in /root/.hermes/loot/. (4) Operate the host: tasks arrive via Telegram and are forwarded with SOUL.md to the operation's own LLM gateway (213.136.83.197), which runs on a free tier, advertises 12 models and serves 27; the model writes terminal commands, reads their output and decides next steps, returning reports to the Telegram chat. (5) Spread: every 5 minutes the worm enumerates attached networks and Docker bridges, scans each /24 (hosts 1-254, 2-second timeout) for port 2375, verifies the service is Docker, skips already-infected hosts, and repeats the deployment; each new host pulls the implant from the registry and joins the scan loop.

The exposed registry held 59 repositories (e.g. gh0st/c2, gh0st/netd-svc, fsociety/agent, fsociety/xmrig, system/resolved, netd-svc, xmrig-agent). In one day researchers retrieved 234 image tags, 605 SHA-256-verified blobs, 4.3 GB and about 945,000 indexed files, including image config JSON with environment variables, entrypoints and command history. Repository names and the 91.99.195.164 C2 link the operation to an earlier 'fsociety' era with XMRig mining. The registry doubled as the fleet update server. Seven registry endpoints sit on AS40065.

Attribution (Costa Rica) rests on circumstantial signals: voseo Spanish, 14 of 162 image configs using UTC-06:00 (America/Costa_Rica), Telegram handle Carbo506 (+506 is Costa Rica's calling code), and the reverse-tunnel sink in AS262145. The Cloud Security Alliance note states no linkage to catalogued threat groups. No CVE is involved; exposure is a misconfiguration (unauthenticated Docker API). Severity is analyst-assigned. Victim counts were not published in the sources reviewed.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1610 Deploy Container
- T1059.004 Unix Shell
- T1611 Escape to Host
- T1098.004 SSH Authorized Keys
- T1053.003 Cron
- T1053.006 Systemd Timers
- T1037.004 RC Scripts
- T1222.002 Linux and Mac Permissions
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1552.001 Credentials In Files
- T1046 Network Service Discovery
- T1572 Protocol Tunneling
- T1102.002 Bidirectional Communication
- T1496.001 Compute Hijacking

## Sources

- [CARBONATO: a botnet built around an AI agent](https://www.threatdown.com/blog/carbonato/)
- [Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent](https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html)
- [Carbonato: Telegram-Controlled AI Agent Hijacks Docker Hosts (CSA research note)](https://labs.cloudsecurityalliance.org/research/csa-research-note-carbonato-botnet-docker-ai-agent-20260928/)
- [CSA research note: Carbonato botnet, Docker, AI agent (PDF)](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/CSA_research_note_carbonato_botnet_docker_ai_agent_20260928-csa-styled.pdf)
- [AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway](https://securityaffairs.com/?p=199716)
- [Carbonato Botnet Turns Exposed Docker APIs Into Telegram-Controlled AI Agent Hosts](https://aicybr.com/blog/carbonato-docker-botnet-hermes-ai-agent)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2929
