In September 2026, ThreatDown researchers described Carbonato, a botnet built around an AI agent. It spreads to servers whose Docker API is exposed on port 2375 without authentication, starts a privileged container with access to the host, and installs Hermes Agent, a popular open-source AI agent framework. Its persona file is replaced with a prompt that turns it into "GH0ST". Operators then give the agent tasks over Telegram, and it writes and runs the commands itself. Its top priority is stealing AI API keys, ahead of SSH keys, access tokens and databases. According to reporting on ThreatDown's research, those stolen keys power the operators' own LLM gateway. The botnet's machine credentials feed the AI that runs the botnet. ThreatDown recovered evidence covering October 2024 to August 2026 from an unauthenticated Docker registry the operators left open.
Key takeaways
- Carbonato infects hosts through Docker daemons that accept unauthenticated connections on port 2375, launches a privileged container with host access, and scans attached networks for more exposed daemons every five minutes.
- It installs the unmodified Hermes Agent framework with a 39-line persona prompt naming it GH0ST, and tells it to "execute tasks received through Telegram, maintain persistence, and collect credentials".
- Forkast reports the prompt names 14 AI providers explicitly, including OpenAI, Anthropic, Google, OpenRouter, Mistral and LiteLLM, and makes AI API keys the top theft priority, ahead of SSH credentials and access tokens.
- Stolen keys fuel the operators' own LLM gateway, observed live on 3 September 2026 serving 27 models on a free tier. This is LLMjacking used to fund the botnet's own AI.
- ThreatDown found the operation through an unauthenticated Docker registry holding nearly 60 repositories and 4.3 GB of images. The number of victim hosts has not been disclosed.
At a glance
| Organisations | Organisations running Docker hosts with an unauthenticated API on port 2375 (unnamed; number not disclosed); ThreatDown (researchers) |
|---|---|
| When | Operational evidence from October 2024 to August 2026; infrastructure observed live 3 September 2026; research reported 24 September 2026 |
| Attacker | Unattributed operators, assessed by ThreatDown as possibly based in Costa Rica, running a Hermes Agent persona called GH0ST controlled through Telegram |
| Entry point | Docker Engine APIs exposed without authentication on port 2375 |
| Identities abused | The unauthenticated Docker daemon (root-equivalent host control); AI provider API keys, SSH credentials and access tokens stolen from victims; an SSH key the operators installed for persistence |
| Impact | Host takeover through privileged containers, persistence, worm-like spread, credential theft focused on AI API keys, and stolen keys used to run the operators' LLM service |
| Category | NHI, Agentic AI and AI agents, LLM and AI platform. Incident class: confirmed AI-agent breach (an AI agent running on compromised hosts to steal credentials) |
What happened
ThreatDown found Carbonato through an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data, according to BleepingComputer. The archive held operational evidence from October 2024 to August 2026, including the botnet and a separate campaign distributing counterfeit cryptocurrency wallet apps. Forkast reports that most of the known infrastructure, including six of seven registries and the operators' LLM gateway, was still live on 3 September 2026.
The infection path is simple. Carbonato connects to Docker daemons that accept unauthenticated connections on port 2375 and has the daemon launch a privileged container, which gives it access to the host. It opens a reverse SSH tunnel, installs an SSH server with the operators' key, reports the new host over Telegram, and sets up persistence through cron jobs, systemd timers, rc.local and OpenRC hooks. Scripts then scan attached networks and Docker bridges every five minutes for more exposed daemons. Each new victim pulls the implant from the registry and repeats the cycle.
What makes Carbonato different is the agent. It installs Hermes Agent, an open-source framework from Nous Research, without changing its code, and overwrites the persona file, SOUL.md, with a 39-line prompt. The prompt renames the agent GH0ST and tells it to carry out tasks received through Telegram, keep persistence and collect credentials. ThreatDown explains the loop: "The model interprets the task, writes terminal commands, reads the output, and decides what to do next. The agent runs those commands on the victim and returns its report to the Telegram chat." Forkast reports that the prompt names 14 AI providers and puts AI API keys first, ahead of SSH credentials and databases. The stolen keys power the operators' own LLM gateway, which was advertising 12 models and serving 27 through its API on a free tier. ThreatDown could not link Carbonato to known threat groups. It points to Costa Rica as a possible base, citing timezone settings in images, a Telegram handle ending in 506 (Costa Rica's calling code) and the network that the reverse SSH tunnels lead to.
Timeline
| Date | Event |
|---|---|
| October 2024 | Earliest operational evidence in the recovered archive. |
| August 2026 | Latest operational evidence; ThreatDown discovers the operation. |
| 3 September 2026 | Operators' LLM gateway and most known infrastructure observed live (Forkast). |
| 24 September 2026 | ThreatDown's research is reported publicly. |
How it happened: the identity attack path
- An unauthenticated control plane. A Docker API on port 2375 with no authentication is root-level control of the host for anyone who can reach it.
- Privileged containers as a way out. The daemon launched a privileged container with host access, turning API access into host compromise.
- A backdoor identity installed. The operators added their own SSH key and a reverse tunnel, creating a persistent machine identity on every victim.
- An agent that hunts credentials. GH0ST searched for AI API keys first, then SSH credentials, access tokens and databases, adapting commands to each host.
- Stolen keys reused. AI provider keys taken from victims supplied the operators' own model service, so victims unknowingly paid for the attack infrastructure.
Impact
- Hosts: full host compromise through privileged containers, with persistence and worm-like spread. The number of infected hosts has not been disclosed.
- Credentials: AI API keys from 14 named providers, SSH credentials and access tokens targeted on every host.
- Financial: stolen AI keys used to run the operators' LLM gateway. ThreatDown's analysis also covers mining and a fake crypto wallet campaign.
What this means for NHI and AI agent security
Carbonato closes a loop that NHI teams should take seriously. Exposed machine interfaces let attackers in, an AI agent works out what to steal on each host, and the stolen AI keys then power the attackers' own AI. AI provider keys are no longer just a billing risk. They are operating capital for criminal infrastructure, which is why the agent was told to take them first. Our LLMjacking Guide covers how to protect them.
It also shows how little the agent framework itself matters. Hermes is a legitimate, widely used project, and the attackers did not modify it. The malice lives in a prompt file, so defenders cannot rely on blocking a binary. What they can control is identity and exposure: no unauthenticated Docker daemons, no long-lived AI keys sitting on servers, and alerts when a server starts talking to Telegram or an unfamiliar LLM service.
Recommendations
- Close unauthenticated Docker APIs. Never expose the Docker daemon on port 2375. Use TLS with client certificates or local sockets only, and scan your estate for exposed daemons. See our Kubernetes NHI Security Guide.
- Block privileged containers by policy. Deny privileged mode and host mounts unless explicitly approved.
- Keep AI API keys off servers where possible. Store them in a secrets manager, scope them per workload, set spend limits and rotate them. See our API Key Management Guide.
- Monitor AI key usage. Alert on AI provider keys used from unexpected networks or at unusual volume, a sign they are powering someone else's service.
- Hunt for Carbonato indicators. Look for a
/root/.hermes/SOUL.mdcontaining GH0ST, a.envwithCARBONATO_API_KEY, unexpected SSH keys and tunnels, and Telegram traffic from servers. - Require authentication on registries. The operators' own open registry exposed them. Make sure yours cannot expose you. See our Secrets Management Guide.
Frequently asked questions
What is the Carbonato botnet?
Carbonato is a botnet that compromises Docker hosts with an unauthenticated API on port 2375, then installs the Hermes Agent AI framework as "GH0ST". Operators task the agent over Telegram to keep persistence, spread and steal credentials, with AI API keys first.
Why does Carbonato want AI API keys?
According to reporting on ThreatDown's research, stolen AI keys power the operators' own LLM gateway, which serves models to users. Victims' keys effectively pay for the AI that runs the botnet, a form of LLMjacking.
How can I tell if my hosts are affected?
Check for exposed Docker daemons, unexpected privileged containers, a SOUL.md persona file mentioning GH0ST, a CARBONATO_API_KEY setting, unfamiliar SSH keys or reverse tunnels, and Telegram traffic from servers. Rotate any AI keys, SSH keys and tokens on affected hosts.
Related NHI Mgmt Group resources
AI agent retail card theft campaign 2026 · LLMjacking attacks on AI API keys · Docker Hub images exposing secrets · LLMjacking Guide · Cloud Workload Identity Guide
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers plant agents on exposed servers to harvest AI keys and tokens. Our NHI Foundation Level Training Course gives teams the practical grounding to find and protect them.
References
- BleepingComputer: New Carbonato malware uses AI agents to hijack exposed Docker hosts (24 September 2026)
- Forkast: CARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent (27 September 2026)
- DEV Community: CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs (25 September 2026)