Carbonato botnet exploits exposed Docker daemons
๐ Cybersecurity researchers disclosed a new botnet named Carbonato that targets unauthenticated Docker daemons to deploy the open-source Hermes Agent AI framework. The malware installs the agent, overwrites its SOUL.md persona to accept Telegram commands, and uses privileged containers, reverse SSH tunnels, cron jobs and watchdogs to maintain persistence and propagate. ThreatDown traced artifacts to an exposed Docker registry and found the campaign includes other malicious operations such as trojanized crypto wallets.
