Cybersecurity researchers have identified a new botnet malware called Carbonato that is targeting exposed Docker daemons to deploy an open‑source artificial intelligence (AI) agent framework known as Hermes Agent.
The discovery was made by the security team at ThreatDown, who noted that the malware specifically seeks out Docker environments that have been left unsecured, allowing it to gain remote access and install its payload.
Once the implant has accessed a Docker host, it installs the Hermes Agent framework unchanged. The malware then overwrites the framework’s SOUL.md persona file, effectively re‑configuring the agent’s behavior for malicious purposes.
The 39‑line prompt directs it to execute tasks received through
Hermes Agent is an open‑source AI framework that can be directed to perform a variety of tasks. By repurposing it through the Carbonato botnet, attackers can issue commands to compromised hosts via the overwritten persona file, turning the AI into a tool for automated malicious activity. The incident underscores the importance of securing Docker daemons and monitoring for unusual deployments of AI frameworks.
<small>Source: The Hacker News — read the original story there.</small>