Carbonato botnet commands hijacked Docker hosts via Telegram and a SOUL.md file

Security firm ThreatDown uncovered a botnet campaign in August 2026 that stands apart from earlier malware: instead of a static command-and-control server, an autonomous AI agent serves as the C2 engine itself.

Illustration: rows of pale gray container-like blocks hang like marionettes on thin black strings converging toward a single mechanical lever out of frame, visualizing hijacked Docker hosts remotely steered by an autonomous agent.
Illustration
Gift article

Carbonato botnet commands hijacked Docker hosts via Telegram and a SOUL.md file

Security firm ThreatDown uncovered a botnet campaign in August 2026 that stands apart from earlier malware: instead of a static command-and-control server, an autonomous AI agent serves as the C2 engine itself. The campaign, named Carbonato, had according to operational data the researchers managed to recover been active since October 2024 – nearly two years without detection. The findings were made public in September 2026, and according to Yahoo Tech/Forkast, this is the first documented case where an AI agent constitutes the core of a botnet's control infrastructure.

A new threat model: the agent replaces the C2 server

Carbonato is a Docker-based botnet in which an autonomous AI agent functions as the command-and-control engine instead of a fixed server. According to Yahoo Tech/Forkast, this is the first documented instance in which C2 infrastructure reasons through its environment and adapts to the specific configuration of each infected host.

The difference from traditional botnet architecture is substantial. A classic C2 server is a fixed address that can be blocked, taken down, or linked to an attacker. An AI agent steered via a prompt needs no fixed infrastructure: it receives orders through a commercial messaging service, interprets them itself, and adapts execution to the machine it runs on. That makes both detection and remediation harder – and it makes the agent's "reasoning" part of the attack tooling, not merely something the attacker uses in support.

How the hosts are hijacked: port 2375 and privileged containers

The entry door is a well-known misconfiguration. Carbonato scans for Docker daemons that accept unauthenticated connections on port 2375, reports Cyberpress. This is the Docker API without authentication.

When Carbonato finds such a host, it connects to the API and instructs the daemon to start a privileged container, according to BleepingComputer. A privileged container has, according to the source, access to the host machine itself, effectively breaking down the isolation containers normally provide.

The spread has, according to CNews, worm-like functionality: the botnet propagates between vulnerable Docker hosts on its own, with the API left open on port 2375 without authentication as the shared weakness.

The AI layer: untouched Hermes Agent, a rewritten SOUL.md

The most technically striking part is what happens after the host is captured. Carbonato installs the Hermes Agent AI framework on the host – but leaves the framework itself unchanged, according to ThreatDown. Instead, the implant overwrites the persona file SOUL.md.

By rewriting this file, the attacker does not need to modify or bypass the agent software itself – they rely on the agent following the instructions in the persona file. The new persona consists of a 39-line prompt that, according to ThreatDown, orders the agent to carry out tasks received via Telegram, maintain persistent access to the host, and collect credential information.

The Telegram channel thus serves as the new control plane. The attacker sends orders in a message thread, the agent reads them as part of its task execution and acts on them. There is no C2 domain to blacklist – only traffic toward an ordinary messaging service. CNews points to unexpected Telegram activity as a visible sign of attack.

Key hunting across 14 AI providers

The 39-line prompt is also highly specific in one area: it explicitly names 14 providers whose API keys the agent is to obtain – OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM and One API, according to Yahoo Tech.

The goal is to power the botnet's own LLM gateway: stolen keys from commercial AI services are to cover the agent's compute needs so the attacker does not have to pay for them. According to the named list, the list covers the full spectrum – from large commercial platforms like OpenAI and Anthropic to local solutions like Ollama and vLLM, as well as middleware layers like LiteLLM and One API that can aggregate keys from multiple providers in one place.

ThreatDown describes the acquisition of API keys as the agent's prioritized objective. It is unclear how many organizations have actually had keys stolen; this is not documented as fact for all infected hosts, but as the agent's designed mission.

The scale: nearly two years, and a registry left open

The researchers found the operation through an unauthenticated Docker registry that had been publicly exposed since May 2026. A single day of read-only collection yielded 59 repositories, 234 image tags and 4.3 GB of image data, according to Cyberpress.

The operational data ThreatDown managed to recover covers the period October 2024 to August 2026 – nearly two years of activity that, according to CNews, remained undetected the entire time.

It is unknown how many hosts are infected. No total scope is known from the published material, and that is a significant open question for anyone running Docker hosts with the API exposed.

Attribution: pointing to Costa Rica, but unconfirmed

ThreatDown has not been able to link Carbonato to any known threat cluster. Based on various pieces of evidence, the firm nevertheless points to Costa Rica as a possible operator location. This attribution is, according to BleepingComputer, unconfirmed, and nothing is known about who the operator is or what motive lies behind it beyond what the prompt and the functionality reveal.

What organizations should do now

The attack vector is closed by measures that are well known but that, as Carbonato shows, are still not consistently followed:

  • Authenticate the Docker API and close port 2375 to the internet. Unauthenticated Docker daemons are the entire entry door for the campaign.
  • Key hygiene for AI services. API keys for the 14 named providers should be stored securely, rotated regularly, and monitored for abnormal use, especially in environments where containers have access to them.
  • Monitor for unexpected Telegram traffic. CNews highlights unexpected Telegram activity as the most characteristic sign of attack from infected hosts.
  • Look for untouched agent frameworks with modified persona files. The fact that Hermes Agent is installed unmodified makes file integrity checks of the framework itself useless – deviations in SOUL.md and similar configuration files, on the other hand, are a clear trail.

Open questions

Several significant questions remain unanswered. How many hosts are infected, and in which organizations? Have API keys actually been stolen at scale, and have they been used via the botnet's LLM gateway? Who is behind it, and were the Costa Rica indications correct? And why was a campaign with worm-like spread and nearly two years of operation not detected by any of the affected hosts before a security firm found the registry?

That last point points toward perhaps the most important consequence of the finding: the attack model in which an AI agent reasons its way forward on each host, communicates via an ordinary messaging service, and procures its own compute with stolen keys, leaves few of the classic indicators security teams usually build detection on. Carbonato is the first documented case – but the architecture requires no single components that do not already exist in openly available tools.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.