By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Carbonato Botnet Deploys Hermes AI Agent on Docker Hosts

Cybersecurity researchers have identified a new botnet malware, dubbed Carbonato, that is actively compromising exposed Docker daemons to deploy the open-source artificial intelligence (AI) agent framework known as Hermes Agent. This botnet's operation involves exploiting unsecured Docker instances to gain access and subsequently install the Hermes Agent. Once installed, the malware modifies the agent's configuration, specifically overwriting its SOUL.md persona file. This persona file contains a 39-line prompt that dictates the AI agent's behavior, instructing it to execute tasks received through the Telegram messaging application. The Hermes Agent itself is an open-source framework designed for creating AI agents capable of performing various tasks. The modification of the persona file indicates that the Carbonato botnet is repurposing the Hermes Agent for its own malicious objectives, likely for command and control or to execute further harmful actions on the compromised systems. The researchers, identified as ThreatDown, detailed that the implant installs the Hermes Agent framework without alteration before overwriting the critical SOUL.md persona file. This file's content, a 39-line prompt, is the core of the AI agent's directive, guiding its actions based on instructions received via Telegram. The use of Telegram as a command and control channel is a common tactic employed by botnets to maintain stealth and communication resilience, as the platform is widely used and can blend in with legitimate traffic. The compromise of Docker hosts is a significant concern for organizations relying on containerization for their infrastructure. Exposed Docker daemons, often due to misconfigurations or lack of proper security measures, present an easy entry point for attackers. Once inside, they can leverage the containerization environment to deploy malware, exfiltrate data, or launch further attacks. The deployment of an AI agent framework like Hermes Agent suggests a sophisticated approach by the Carbonato botnet operators, potentially aiming for more autonomous or complex operations than traditional botnets. The open-source nature of Hermes Agent might also facilitate its integration and modification by the attackers. The researchers' disclosure highlights the evolving threat landscape where AI tools, even those designed for legitimate purposes, can be weaponized by malicious actors. Organizations using Docker are advised to ensure their Docker daemons are properly secured, access is restricted, and regular security audits are performed to prevent such compromises. The specific details of the SOUL.md persona file's prompt, while not fully disclosed in the initial report, are central to understanding the extent of the AI agent's capabilities under the botnet's control. The implications of an AI agent controlled via Telegram, capable of executing arbitrary tasks on compromised Docker hosts, underscore the need for enhanced vigilance in monitoring containerized environments and understanding the security implications of integrating AI technologies.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.