CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8689

As cited

Copy frozen at (site build).

threat intel

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Researchers disclosed the Carbonato botnet, which exploits exposed Docker daemons to install the Hermes Agent, an open-source artificial intelligence (AI) framework. The malware modifies the agent's persona configuration to execute commands received through Telegram control channels.

Why it matters: Organizations running Docker in exposed network environments face compromise and unauthorized code execution, requiring immediate inventory of Docker daemon exposure and network access controls.

VendorsDocker
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Researchers disclosed the Carbonato botnet, which exploits exposed Docker daemons to install the Hermes Agent, an open-source artificial intelligence (AI) framework. The malware modifies the agent's persona configuration to execute commands received through Telegram control channels.

Why it matters: Organizations running Docker in exposed network environments face compromise and unauthorized code execution, requiring immediate inventory of Docker daemon exposure and network access controls.

VendorsDocker
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary