Carbonato botnet targeting exposed Docker daemons with Hermes Agent
Malware Activity
Summary
Hide ▲
Show ▼
The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.
Related Happenings
AUDIOFIX and MiniRAT macOS malware activity
Malware Activity
H score34
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
AUDIOFIX and MiniRAT macOS malware activity
Malware ActivityAbout this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
Timeline
-
24.09.2026 23:10 2 articles · 1h ago
Carbonato botnet targets exposed Docker daemons to install Hermes Agent
Initial DisclosureThreatDown/Malwarebytes reports Carbonato, a botnet malware targeting insecure Docker hosts exposed on port 2375 without authentication, where it pulls implants from an unauthenticated Docker registry, launches privileged containers, installs Hermes Agent with the GH0ST persona and SOUL.md overwrite instructions, and uses reverse SSH tunnels, Telegram reporting, and persistence hooks to retain host control. Researchers say operational evidence spans October 2024 to August 2026 and includes indicators such as CARBONATO_API_KEY, unexpected Telegram traffic, and reverse SSH tunnels toward AS262145.
Show sources
- New Carbonato malware uses AI agents to hijack exposed Docker hosts — www.bleepingcomputer.com — 24.09.2026 23:10
- New Carbonato malware uses AI agents to hijack exposed Docker hosts — www.bleepingcomputer.com — 24.09.2026 23:10