Carbonato Botnet Leverages AI Framework to Automate Commands and Steal Cloud Credentials

The Carbonato botnet is deploying the open-source Hermes Agent AI framework to compromise Docker container environments and enable remote command execution via Telegram. The malware targets exposed Docker hosts to harvest AI API keys and other sensitive credentials stored on containerized systems. The campaign demonstrates how threat actors are integrating autonomous AI agents into botnet infrastructure to scale operations.
The Carbonato botnet represents an evolution in malware tactics, combining automated AI agent technology with traditional botnet infrastructure. By adopting the Hermes Agent framework, attackers have created a system capable of executing commands at scale without constant manual intervention. This approach allows the malware to operate more efficiently across compromised Docker environments.
The campaign specifically targets containerized systems with exposed Docker interfaces, seeking to extract API credentials and other authentication tokens. These stolen credentials provide attackers with direct access to cloud services and AI platforms, potentially enabling further compromise of downstream systems and data stores.
Organizations relying on containerized infrastructure and cloud services may face increased risk from this evolving threat model. Development teams, DevOps personnel, and cloud security administrators could be particularly affected if their Docker environments lack proper access controls or credential isolation. The integration of AI automation into botnet operations may signal a broader trend that could complicate threat detection and incident response efforts across the technology sector.