Find notable cyber news and cases, enriched with sources, timelines, and signals.

Carbonato botnet targeting exposed Docker daemons with Hermes Agent

Malware Activity
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.

Related Happenings

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

Timeline

  1. 24.09.2026 23:10 2 articles · 1h ago

    Carbonato botnet targets exposed Docker daemons to install Hermes Agent

    Initial Disclosure

    ThreatDown/Malwarebytes reports Carbonato, a botnet malware targeting insecure Docker hosts exposed on port 2375 without authentication, where it pulls implants from an unauthenticated Docker registry, launches privileged containers, installs Hermes Agent with the GH0ST persona and SOUL.md overwrite instructions, and uses reverse SSH tunnels, Telegram reporting, and persistence hooks to retain host control. Researchers say operational evidence spans October 2024 to August 2026 and includes indicators such as CARBONATO_API_KEY, unexpected Telegram traffic, and reverse SSH tunnels toward AS262145.

    Show sources