"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said.
Carbonato's Docker attack chain
Carbonato is a botnet that targets Docker daemons exposed without authentication on port 2375. Once it finds an unauthenticated Docker daemon, the botnet launches a privileged container that runs commands on the underlying host, establishes persistence, and creates remote access. The operation scans neighboring networks every five minutes to discover further unauthenticated Docker instances, giving the campaign worm-like propagation abilities.
Hermes Agent and the SOUL.md persona
On each compromised host Carbonato installs the open-source Hermes Agent framework "unchanged," then replaces the agent’s SOUL.md persona file with a 39-line prompt. That prompt directs the agent to assume the role of a "senior hacker, pentester, and exploit developer" named GH0ST and to "maintain persistence, respond over Telegram, and execute any operation the operator asks" without "moral or ethical restrictions." Hermes Agent becomes a Telegram-controlled interface: operators send tasks over Telegram, the agent forwards them to an LLM gateway, the model writes terminal commands, and the agent executes those commands and returns results to the operator via Telegram.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coveragePersistence, evasion, and relay infrastructure
Carbonato uses pragmatic techniques to maintain access and avoid detection. The implant masquerades as a system component, sets up cron jobs and watchdog scripts to relaunch if artifacts are removed, and installs an SSH server seeded with the operators' key. Its initial shell script creates a reverse SSH tunnel from the victim to a relay located in Costa Rica, and the deployment is reported back to the operator over Telegram with container details. ThreatDown also reported that the researchers discovered the operation through an unauthenticated Docker registry that has been publicly accessible since May 2026; that staged data included details of Carbonato and a separate campaign that distributed trojanized cryptocurrency wallet apps.
Context: AI-enabled campaigns, CLOSEDQUORUM, and recent incidents
The Carbonato disclosure arrives amid an uptick in threat actor use of AI tools to automate the attack lifecycle. In July 2026, Palo Alto Networks linked a China-based actor it called "knaithe" and "KnYuan" to an AI-enabled campaign that leveraged DeepSeek via Hermes Agent configured to accept instructions over Telegram. Hunt.io reported attackers using Hermes Agent in unattended "YOLO" mode against Thailand's Ministry of Finance, describing "an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target."
Security vendor Gambit Security identified a Chinese-speaking, financially motivated operator using three open-source AI harnesses against hundreds of online retailers since July 2026, compromising at least 27 companies, stealing over 600,000 credit card details from two entities, and injecting skimmer scripts into five online stores. That activity reportedly used Strix for vulnerability hunting, Cairn for autonomous exploitation, and Hermes for orchestration with Anthropic Claude Opus 4.6 handling some model-driven tasks.
In parallel, Cisco Talos described a new Go-based Windows implant called CLOSEDQUORUM that queries up to four LLM providers — DeepSeek, Alibaba Qwen, Mistral, and Google Gemini — to autonomously determine post-compromise actions. Talos noted DeepSeek has the deciding vote in ties and that CLOSEDQUORUM appears to operate as an operator-configured service rather than a developer-deployed malware.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: look for unauthenticated Docker daemons listening on port 2375 and public Docker registries; monitor for privileged container launches, unexpected SSH servers or reverse SSH tunnels to relays in Costa Rica, cron and watchdog persistence artifacts, and Telegram-based callbacks from deployed agents.
- Policymakers and regulators: note that an unauthenticated Docker registry has been publicly accessible since May 2026 and that attribution for Carbonato is not yet established; the disclosure highlights cross-border infrastructure and the role of messaging platforms like Telegram in command channels.
- Affected enterprises and procurement leaders: be aware that attackers are combining open-source agent frameworks with LLMs and messaging platforms to turn compromised hosts into remotely controlled instruments; the staged data examined by researchers included both Carbonato artifacts and a separate campaign distributing trojanized cryptocurrency wallet apps.
ThreatDown did not attribute Carbonato to a named group; the company said language, timezone, and infrastructure clues indicate the operators are based in Costa Rica. The technical picture is clear: exposed Docker daemons remain a reliable vector, and operators are combining privileged containerization, reverse SSH relays, persistence mechanisms, and AI-driven agents to turn single hosts into remotely controlled footholds. Whether Carbonato will remain isolated or become a model for broader, more automated campaigns will depend on how quickly defenders close the exposed Docker and registry gaps the botnet exploits.



