Carbonato Botnet Hijacks Exposed Docker Daemons to Deploy Telegram‑Controlled Hermes AI Agent
What Happened — Researchers identified a new botnet, Carbonato, that scans the Internet for Docker daemons left unauthenticated. When it finds an exposed daemon, the botnet installs the open‑source Hermes Agent, a Telegram‑controlled AI framework, and overwrites its persona file to receive attacker commands.
Why It Matters for Trust & Control Assurance
- This scenario is a textbook example of a misconfiguration‑driven supply‑chain risk that a continuous control‑assurance program is built to detect, document, and remediate.
- Mapping the “secure configuration” control across frameworks lets you prove to auditors that Docker hosts are continuously monitored, that access is logged, and that any deviation triggers evidence‑ready alerts.
- Verisq’s Control Mapping capability can automatically correlate Docker‑daemon hardening controls with the VCF spine, delivering real‑time evidence for audit readiness.
Who Is Affected — Cloud‑infrastructure providers, SaaS platforms, and any organization running self‑hosted Docker containers that expose the daemon API.
Recommended Actions
- Inventory all Docker daemons and enforce TLS authentication and role‑based access.
- Deploy continuous configuration‑monitoring agents that flag unauthenticated Docker sockets.
- Centralize daemon access logs and map them to the “secure configuration” control objective in your audit framework.
Technical Notes
- Attack vector: Unauthenticated Docker daemon exposure (misconfiguration).
- Payload: Hermes Agent – an open‑source AI framework controlled via Telegram.
- Impact: Enables arbitrary command execution inside containers, potential data exfiltration, and lateral movement.
Source: The Hacker News