Malware · 14h ago
Carbonato is targeting exposed Docker daemons to take over container hosts and install the Hermes Agent AI framework. BleepingComputer says the malware is using that exposed management interface as the entry point, so a reachable daemon is enough to turn a server into botnet infrastructure.
The key boundary is the Docker control plane. Carbonato does not need to break into a container; it talks to Docker’s management interface directly, then uses it to start and manage whatever it wants on the host. That means the compromise is not confined to one container, because the daemon can steer the whole machine.
For teams running Docker Engine, the exposure sits wherever the daemon is reachable from the network instead of only from localhost or a trusted management network. Once that control plane is open, the host can be remotely steered and folded into someone else’s botnet operations, with AI agents speeding up post-compromise management and spread.
1 source covering this story
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
Part of the PlainSec briefing for 2026-09-25