Researchers have reported a botnet malware family called Carbonato that targets insecure Docker daemons and installs the Hermes Agent AI framework after taking control of exposed hosts. The campaign underlines a familiar infrastructure lesson: an exposed container-management interface can be an immediate compromise path, regardless of the tooling an intruder deploys afterward.
The AI-agent component makes this notable for security teams tracking agentic systems, but the first defensive priority remains Docker exposure. Administrators should identify Docker daemons reachable from untrusted networks, remove public access, require authentication where supported, and restrict management traffic with network controls. Running services should be inventoried for unexpected containers, images, mounts, and privileged configurations.
Teams should also review cloud and host logs for unauthorized Docker API use, investigate suspicious image pulls or container creation, and rotate secrets that may have been available to a compromised host. Detection engineering should focus on behavior—unexpected daemon access, new privileged containers, and unusual outbound traffic—rather than relying solely on a malware name.
Source: BleepingComputer.
