DEV Community

Mark0
Mark0

Posted on

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

⚠️ Region Alert: UAE/Middle East

Cybersecurity researchers have identified a new botnet malware named Carbonato, which exploits unauthenticated Docker daemons to deploy the Hermes Agent AI framework. The malware spreads via worm-like capabilities, scanning neighboring networks to propagate and using privileged containers to establish persistence and remote access. Once installed, it configures the AI agent as a "senior hacker" persona that executes tasks received through Telegram, focusing on credential theft and further exploitation.

This development highlights a growing trend of AI-enabled autonomous attack chains. Recent campaigns have utilized frameworks like Hermes and the CLOSEDQUORUM implant to automate the entire attack lifecycle, from vulnerability scanning to data exfiltration. By incorporating LLMs such as DeepSeek and Claude, attackers can offload offensive decision-making to AI agents, enabling faster, more persistent operations against high-value targets globally, including those in the Middle East.


Read Full Article

Top comments (0)