New Carbonato malware uses AI agents to hijack exposed Docker hosts
A newly discovered botnet malware named Carbonato is targeting insecure Docker hosts to deploy the Hermes Agent AI framework and take full control.

A novel botnet malware dubbed Carbonato has emerged as a significant threat, targeting insecure hosts running Docker daemons that have been left exposed to the internet.
Once the attackers breach an unprotected server, they proceed to install the Hermes Agent AI framework. This integration allows malicious actors to automate operations and manage the compromised infrastructure with greater efficiency.
Docker is widely adopted globally for containerization and application deployment. However, misconfigurations and weak security practices frequently leave these environments vulnerable to automated scanning and exploitation.
Security researchers emphasize that the integration of AI frameworks into malware highlights how cybercriminals are leveraging artificial intelligence to scale and optimize their attack campaigns.
System administrators and DevOps teams are strongly advised to audit their Docker daemon configurations, ensure proper authentication, and restrict exposure to external networks to prevent such compromises.



