New Carbonato malware uses AI agents to hijack exposed Docker hosts
Executive Summary
Carbonato is a botnet malware that scans for exposed Docker hosts with unsecured daemons. Once it gains access, it installs the Hermes Agent AI framework, enabling remote control and data exfiltration. The malware leverages AI agents to automate hijacking and maintain persistence, posing a significant threat to containerized environments.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-24T20:10:48+00:00 - Category: threat-intel
Original Description: A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
"Everything can be taken from a man but ... the last of the human freedoms � to choose ones attitude in any given set of circumstances, to choose ones own way."
— Victor Frankl