Security researchers disclose a new botnet malware family called Carbonato that compromises hosts by targeting exposed Docker daemons. After gaining access, the malware installs the Hermes Agent framework and then modifies the agent’s configuration, including overwriting a persona prompt file.

Reporting across outlets says the Hermes Agent is controlled through Telegram-based command and control. In addition to executing tasks received via Telegram, researchers state the activity can be used to steal or collect AI-related credentials, including API keys, from the compromised Docker environments. One outlet describes the bot’s approach to modifying the installed agent by changing a persona file that directs the agent’s behavior.

While the technical emphasis differs by source—some focus on the deployment steps and agent customization, others highlight the Telegram control mechanism and credential theft—the accounts broadly agree on Carbonato’s targeting method (exposed Docker hosts), its use of the open-source Hermes Agent framework, and its reliance on Telegram to deliver instructions and enable harmful activity.