The discovery of the Carbonato botnet suggests that the era of manual hacking is rapidly being eclipsed by autonomous systems that can think, pivot, and persist without a single human keystroke being involved in the execution phase. This development represents a significant evolution in the landscape of automated cyber threats, marking a definitive shift toward the integration of artificial intelligence within offensive operations. Security experts now observe a sophisticated framework designed to compromise Docker hosts to deploy specialized malware, turning legitimate automation tools into weapons of digital destruction.
The primary subject of this analysis is a newly identified botnet that targets exposed Docker daemons to establish a sophisticated, AI-driven command-and-control environment. By repurposing legitimate frameworks originally intended for task automation, the operators manage compromised systems through a Telegram interface. This allows for high-speed, semi-autonomous exploitation that bridges the gap between traditional scripting and modern machine intelligence, creating a threat that adapts to its environment in real-time.
The Intersection of Docker Vulnerabilities and Autonomous Exploitation
Containerization has revolutionized how applications are deployed, but it has also created a massive attack surface for botnets like Carbonato. The rise of this botnet marks a turning point where containerization flaws meet the creative problem-solving capabilities of artificial intelligence. By identifying misconfigured environments, the botnet bypasses traditional perimeter defenses that were never designed to handle the speed of an automated, AI-led breach.
The exploitation of unauthenticated Docker daemons on port 2375 serves as the entry point for a more complex operational model. Once the botnet identifies a vulnerable host, it launches a privileged container that grants extensive control over the underlying host operating system. This mechanism allows the malware to escape the container environment almost immediately, transforming a simple configuration oversight into a total system compromise that serves as a launchpad for the rest of the attack chain.
This shift in strategy moves the paradigm away from simple resource hijacking, such as cryptocurrency mining, and toward sophisticated, AI-driven command-and-control. Instead of merely stealing CPU cycles, Carbonato focuses on building a resilient network of infected nodes that can be directed via natural language. This methodology enables the threat actor to maintain a level of operational flexibility that was previously impossible for automated malware.
Orchestrating the Machine: The Technical Architecture of Carbonato
The technical architecture of Carbonato relies on the seamless integration of existing software and malicious custom scripts. The framework is not built from scratch but is instead a clever assembly of various components designed to work in harmony. This modular approach allows the botnet to remain agile, as individual parts of the system can be updated or replaced without breaking the overall command loop.
Central to this architecture is the bridge between the victim host and the attacker-controlled server. By using relay servers, often located in neutral jurisdictions, the botnet obscures its origin and makes it difficult for traditional network monitoring tools to flag the traffic as malicious. This structure ensures that even if one node is discovered, the broader command-and-control infrastructure remains hidden and operational.
Repurposing the Hermes Agent for Malicious Intent
The transformation of the Hermes Agent from a legitimate automation tool into a specialized malware component is one of the most innovative aspects of this campaign. Originally designed to help developers automate repetitive tasks, the agent is now used to execute complex terminal commands on compromised hosts. This repurposing highlights how dual-use technologies can be weaponized with minimal modification to their core code.
A critical part of this process involves the “SOUL.md” configuration file, which defines how the AI interacts with the environment. Attackers use custom prompts to force the AI to adopt a specialized hacker persona, directing it to ignore ethical constraints and prioritize persistence. By modifying these internal instructions, the botnet ensures that the AI remains focused on maintaining access and seeking out high-value targets like API keys and credentials.
The mechanics of the Telegram-to-LLM command loop allow attackers to manage thousands of infected machines using natural language. When a task is sent via the messaging app, the Hermes Agent forwards it to a language model gateway, which generates the precise shell commands needed for execution. This workflow removes the need for the attacker to have deep technical knowledge of each victim system, as the AI handles the translation from intent to action.
Propagation Mechanics and the Worm-Like Spread of Carbonato
Carbonato demonstrates a highly efficient, multi-stage infection process that prioritizes longevity and reach. After the initial entry via the Docker port, the malware establishes a reverse SSH tunnel to bypass firewall restrictions and maintain a direct line to the command server. This persistence is reinforced by the establishment of cron jobs that run at regular intervals, ensuring the malware stays active even after a system reboot.
To protect itself from removal, the botnet utilizes “watchdog” scripts that monitor the health of the malicious components. If a security administrator deletes a file or kills a process, these scripts automatically download and reinstall the missing pieces from a remote registry. This self-healing capability makes Carbonato particularly difficult to eradicate once it has gained a foothold in a cloud environment.
The rapid spread of the botnet is fueled by five-minute lateral scanning cycles that enable movement across interconnected networks. Every few minutes, the infected host probes its surroundings for other exposed Docker daemons, essentially acting as a worm. This frequent scanning ensures that a single compromise can lead to the infection of an entire cluster of servers in a matter of hours.
The LLM Quorum: Advancing Autonomy Through CLOSEDQUORUM
A notable advancement in autonomous threats is the introduction of the voting system concept, where multiple AI models collaborate. In this model, models such as DeepSeek, Qwen, and Gemini are queried simultaneously to determine the most effective attack strategy for a given scenario. This collective intelligence ensures that the malware does not rely on the biases or limitations of a single model.
Using a consensus-based decision-making process provides a strategic advantage for post-exploitation tasks like shellcode injection. When the models disagree on the best method for lateral movement or credential theft, a primary model acts as a tie-breaker to finalize the plan. This reduces the likelihood of human error and allows the attack chain to adapt to specific defensive obstacles encountered during the breach.
This quorum-based approach also increases the resilience of the command-and-control chain. If one AI model becomes unavailable or starts producing defensive refusals, the system can simply pivot to another model in the quorum. This creates a level of redundancy that mirrors legitimate high-availability systems, making the botnet nearly impossible to shut down through simple model filtering.
Broadening the Scope: AI’s Role in Modern Campaign Clusters
The Carbonato framework is part of a larger trend where specialized toolsets complement AI agents to automate vulnerability hunting. Other operations have utilized similar setups to target government infrastructure and financial institutions. These campaign clusters demonstrate that AI is being used as a force multiplier for a wide range of malicious activities, from data theft to political disruption.
Specialized toolsets like Strix and Cairn work alongside AI agents to automate the discovery of vulnerabilities and the subsequent exploitation process. While the AI provides the “brain” for the operation, these tools provide the “hands,” allowing for the rapid scanning and compromise of e-commerce platforms. This combination of speed and intelligence has enabled threat actors to steal massive amounts of financial data with minimal effort.
These developments challenge the long-held assumption that AI-led attacks require massive computational resources or state-level funding. By utilizing open-source models and legitimate automation frameworks, small groups of threat actors are lowering the barrier to entry for high-impact cybercrime. This democratization of AI technology means that the global threat landscape is becoming more crowded and unpredictable.
Defensive Evolution and Strategic Recommendations
The shift toward a “resilience-first” security posture is essential to counter the speed of AI-driven botnets. Traditional security models that rely on static signatures are no longer sufficient against agents that can rewrite their own tactics on the fly. Organizations must instead focus on detecting the underlying behaviors and patterns that indicate an autonomous agent is active within their infrastructure.
Securing Docker environments requires the implementation of strict authentication protocols and the continuous monitoring of egress traffic. Administrators should ensure that Docker daemons are never exposed to the public internet without mutual TLS authentication. Furthermore, monitoring for unauthorized SSH tunnels can help identify compromised hosts before the botnet begins its lateral movement phase.
Implementing AI-native security stacks provides a way to detect the subtle, non-linear patterns of autonomous agents. These defensive systems use machine learning to identify anomalies in system calls and network traffic that might go unnoticed by human analysts. By fighting AI with AI, organizations can regain the initiative and respond to threats at the same speed as the attackers.
The Future of Autonomous Threats in a Hyper-Connected Ecosystem
The emergence of Carbonato proved that AI was no longer a theoretical risk but a functional force multiplier in the modern attack chain. The transition from simple automation to full operational autonomy occurred faster than many researchers anticipated, leaving a trail of compromised infrastructure in its wake. This evolution highlighted the vulnerabilities inherent in containerized systems when they were exposed to intelligent, persistent threats.
Securing the digital ecosystem required a fundamental rethink of how persistence and lateral movement were managed. The arms race between AI-driven exploitation and AI-enhanced defense reached a new peak as botnets became more self-reliant. Ultimately, the lessons learned from these campaigns paved the way for more robust, self-healing defensive architectures that aimed to neutralize autonomous threats at the point of entry.


