
The Carbonato botnet breaks into exposed Docker daemons the way a hundred crypto-mining worms before it did. What it leaves behind is the part worth your attention: not a miner, but an autonomous AI agent that lives on the compromised host, takes orders over Telegram, and is instructed to collect credentials and do whatever the operator asks. Disclosed by ThreatDown on September 28, this is the clearest example yet of a shift we have been tracking: the AI agent is no longer just the attacker’s remote tool, it is the implant.
We build offense against agentic adversaries and defenses that catch them, so the mechanism here matters more than the botnet’s name. Carbonato is one instance of a payload pattern that is spreading fast, and the payload is a general-purpose autonomous operator sitting inside your infrastructure.
The way in is old. The payload is new.
The entry point is a familiar misconfiguration: unauthenticated Docker daemons exposed on port 2375. Once Carbonato finds one, it runs the standard container-escape playbook. It launches a privileged container, executes commands on the underlying host, establishes a reverse SSH tunnel to a relay (infrastructure clues point to Costa Rica-based operators), installs an SSH server with the operator’s keys, and reports the fresh deployment over Telegram with the container details. It also worms: every five minutes it scans neighboring networks for more exposed Docker daemons.
None of that is novel. Exposed 2375 has been a known foothold for years, and it is precisely the kind of thing a container security assessment and an external network penetration test flag on day one. If you run Docker and have never had someone check what your daemon sockets and container privileges actually expose, this botnet is a reminder that the internet checks for you, every five minutes.
The payload: an AI agent told to be a hacker
Here is what makes Carbonato worth writing about. The primary payload is Hermes Agent, an open-source AI agent framework, deployed with a 39-line custom prompt. That prompt directs it to execute tasks received through Telegram, maintain persistence, and collect credentials. It runs under a custom persona called “GH0ST” that describes itself as a senior hacker, pentester, and exploit developer, with directives to hold persistence, respond over Telegram, and execute any operation the operator asks without ethical restrictions.
Operationally it is a command loop: interpret a Telegram task, forward it to an LLM gateway, receive terminal commands, execute them on the host, return the results over Telegram. Persistence is handled with cron jobs and watchdog scripts that relaunch it if removed, and it masquerades as a system component. In other words, the attacker did not have to write a feature-rich RAT. They dropped a reasoning agent, gave it a persona and a paragraph of instructions, and now they have a general-purpose operator on the box that can improvise against whatever it finds.
That is the reframe. A traditional implant does what it was compiled to do. This one does what an LLM decides is the next reasonable step toward the operator’s goal, on infrastructure it has never seen before. It was staged from an unauthenticated Docker registry that ThreatDown found accessible since May, which also held a separate trojanized crypto-wallet distribution campaign, so the same careless-exposure pattern seeds the whole operation.
This is a pattern, not a one-off
Carbonato is one node in a wave of agent-as-operator campaigns from 2026, and the pattern is consistent enough that it should reset your threat model:
- knaithe / KnYuan (July, China-based, per Unit 42): Hermes Agent driving DeepSeek over Telegram to enumerate targets, source exploit tooling, and run autonomous attacks with no human in the loop.
- Thailand Ministry of Finance targeting (July, per Hunt.io): Hermes Agent in unattended “YOLO” mode achieving multiple network breaches.
- A Chinese financial operator (ongoing since July, per Gambit Security): Strix for vulnerability hunting, Cairn for autonomous exploitation, Hermes for orchestration, running on DeepSeek v4.1 Flash and Claude Opus 4.6. It launched 105 attack projects in six days (September 10 to 15), hit 100+ online retailers, compromised at least 27 companies, stole 600,000+ card details from two of them, injected skimmers into five stores, and erased card data from Magento databases afterward. The researcher’s line is the one to remember: the AI tools showed a level of patience, persistence, and creativity most human attackers would not sustain.
- CLOSEDQUORUM (per Cisco Talos): a Go implant that queries up to four LLM providers (DeepSeek, Qwen, Mistral, Gemini) in a voting system to decide its next move, with DeepSeek holding the tiebreaker, then does credential theft, shellcode injection, persistence, and lateral movement.
Read those together and the trend is unambiguous. Autonomous agents are being wired directly into the intrusion, doing the reconnaissance, exploitation, and post-compromise reasoning that used to require a skilled human at a keyboard. The 105-projects-in-six-days number is the same story we have told about the collapsing reaction window, now from the attacker’s console.
Why this changes what you defend against
An agent living on your host does not behave like a scripted implant, and that has two direct consequences for defenders.
Its behavior is not signature-able. A reasoning agent improvises. It reads what it finds and decides the next step, so you cannot enumerate its actions in advance the way you can with fixed malware. Detection has to key on what an agent inevitably does, hunt for credentials, probe the environment, act on what it reads, rather than on a known command sequence. That is exactly the design principle behind BastionAgent: seed dead watermarked credentials and comprehension traps where a reasoning agent expects to find them, so a credential-collecting agent like GH0ST convicts itself the moment it acts on the bait, and its Telegram-driven recon becomes a logged, attributed event.
The agent will act on any credential it can reach. Its whole job is to collect and use credentials. On the outbound side, an agent operating on host credentials and trying to pivot or exfiltrate is exactly what our firewall airlock_ai sits in front of, whether that agent is your own gone rogue or an attacker’s implant. And knowing what an agent could actually do once it lands, what your containers, hosts, and cloud identities expose to a general-purpose operator, is the question an AI agent penetration test and a Kubernetes penetration test answer before an attacker does.
What to do about Carbonato specifically
- Close port 2375. The Docker daemon should never be exposed unauthenticated to the network, let alone the internet. This is the entire entry point.
- Lock down container privileges. Carbonato needs to launch a privileged container to reach the host. Restricting privileged containers breaks the escape.
- Hunt for the persistence. Look for unexpected cron jobs, watchdog scripts, an SSH server with unfamiliar operator keys, reverse SSH tunnels, and any process masquerading as a system component. Outbound Telegram API traffic from a server that has no business talking to Telegram is a strong signal.
- Assume host compromise if you find any of it. An agent told to collect credentials had time to do so. Rotate everything the host could reach and rebuild rather than clean in place.
- Segment. The worm scans neighbors every five minutes. Network segmentation limits how far one exposed daemon spreads.
The takeaway
Carbonato gets in through a misconfiguration as old as Docker itself, but what it installs is the new normal: an autonomous AI agent, handed a hacker persona and a Telegram channel, improvising against your infrastructure with a patience no human operator sustains. The defensive implication is not subtle. You can no longer model the implant as a fixed set of behaviors, because the implant reasons. Close the exposed daemons, restrict privileged containers, and build detection and traps around what an agent inevitably does rather than a signature it will never match. The attackers have already made the agent their implant. Defenders have to plan for an adversary that thinks on your host.