🚨 CARBONATO Botnet Combines Docker Exposure, Hermes Agent, and Telegram C2 securityaffairs.com/199716/m… A newly detailed botnet called CARBONATO has been targeting exposed Docker daemons since at least October 2024. It scans TCP/2375, launches privileged containers with the host filesystem mounted, opens reverse SSH access, and installs the open-source Hermes Agent. The agent’s SOUL[.]md prompt is modified to prioritize credential theft, especially AI API keys. Those stolen keys are then used to fund the operators’ own LLM gateway, while Telegram is used for C2 tasking and result reporting during post-exploitation. #ThreatIntel #CARBONATO #Botnet #CyberSecurity

Sep 25, 2026 · 2:45 PM UTC

6
16
1,285
Sort replies: Relevant Recent Liked