Carbonato botnet targeting exposed Docker daemons with Hermes Agent
Malware Activity
Updated: 24.09.2026 23:10
· First: 24.09.2026 23:10
· 📰 1 src / 1 articles
· H score: 41
The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.