malware
Published 2026-09-23
Verified 2026-09-27

CARBONATO (ThreatDown 23 Sep): Docker :2375 worm installs Hermes AI agent GH0ST over Telegram

ThreatDown / Malwarebytes (published 23 September 2026; BleepingComputer amplify 24 Sep) documents CARBONATO, a worm-like botnet that targets Docker daemons exposed without authentication on TCP 2375. Operators (and later the worm) use the Docker API to launch a privileged container with the host filesystem and host PID/network namespaces mounted, then install persistence (cron, systemd timers, rc.local / OpenRC), reverse SSH with an operator key, and Telegram deployment beacons. Post-compromise control is built around the MIT-licensed Hermes Agent framework (Nous Research): the implant leaves the framework intact but overwrites SOUL.md with a 39-line persona naming the agent GH0ST, directing Telegram task execution, persistence, and collection of AI API keys, SSH credentials, tokens and exposed AI endpoints via an operator LLM gateway. ThreatDown recovered the staging Docker Registry (port 5000, unauthenticated) in August 2026 after it had been public since May — about 59 repositories / 234 tags / 4.3 GB spanning October 2024–August 2026, also covering a linked counterfeit cryptocurrency-wallet app factory. Worm periodically scans attached /24s for further :2375 daemons. Distinct from desk gambit-ai-retail-agents-20260922 (Hermes used for retail skimming) and closedquorum-talos-20260922 (Windows LLM-quorum implant). No CVE. Primary: ThreatDown; wire: BleepingComputer 24 Sep 2026.

Product
CARBONATO Docker botnet + Hermes Agent (GH0ST persona) over Telegram
Versions
n/a (malicious implant; targets unauthenticated Docker API on TCP 2375; no CVE)
Exploited in Australia?
unknown
Patch to
Never expose Docker daemon TCP 2375 without TLS client auth; bind Docker API to localhost/VPN only; hunt privileged containers with host mounts + unexpected Hermes/SOUL.md + Telegram beacons; rotate credentials/AI API keys on any host that had an open :2375

Primary: ThreatDown — CARBONATO: a botnet built around an AI agent (23 Sep 2026) · Vendor: ThreatDown / Malwarebytes — CARBONATO analysis · BleepingComputer — Carbonato hijacks exposed Docker hosts (24 Sep 2026)

ai cloud network