Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

A sophisticated botnet has been discovered compromising Docker hosts to deploy a Telegram-controlled AI agent, marking a significant escalation in the threat landscape. Carbonato Botnet, as it’s been dubbed, has successfully infiltrated multiple organizations worldwide, raising concerns about data security and the potential for devastating attacks.

Carbonato works by exploiting vulnerabilities in Docker, a popular platform for containerization, allowing attackers to gain administrative access to affected hosts. Once inside, the botnet deploys an AI-powered agent, codenamed Hermes, which can be remotely controlled via Telegram messaging service. This configuration enables attackers to execute malicious tasks, including data theft and lateral movement across compromised networks.

The scope of the compromise is alarming, with multiple organizations in various industries hit by Carbonato Botnet. Docker hosts from a range of companies have been affected, highlighting the botnet’s ability to target diverse environments. The exploit leverages vulnerabilities in Docker’s internal communication channels, allowing attackers to gain elevated privileges and execute commands as if they were system administrators.

The deployment of Hermes AI agent is particularly concerning due to its advanced capabilities. This autonomous malware can adapt to changing network conditions, making it a formidable foe for security teams. With Telegram control, attackers can remotely instruct Hermes to perform complex tasks, such as data exfiltration or even ransomware attacks. The botnet’s ability to scale and evade detection underscores the need for vigilant monitoring and proactive measures.

As organizations grapple with the aftermath of Carbonato Botnet’s assault, it becomes clear that the exploit is merely a symptom of broader security concerns. Identity exposure and privilege escalation remain significant threats, as highlighted by recent research into cross-domain attacks. The intersection of these risks creates an environment ripe for catastrophic breaches, emphasizing the importance of robust security controls and vigilant monitoring.

In light of this incident, organizations should prioritize securing Docker environments through regular updates, patch management, and strict access control policies. Furthermore, conducting thorough vulnerability assessments can help identify and mitigate potential entry points for attacks like Carbonato Botnet. By staying ahead of emerging threats and prioritizing data protection, businesses can reduce their exposure to devastating cyberattacks.


Source: The Hacker News — 2026-09-28