Security & AI news

AI agent security · By FireAI Security & Research Team · Published

Carbonato botnet installs Hermes Agent on exposed Docker hosts and takes orders through Telegram

ThreatDown reports a botnet that deploys the open-source Hermes Agent on Docker hosts left open on port 2375. What the sources say, and the hardening Hermes documents.

An AI agent icon on a server stack with an open port, illustrating the Carbonato botnet deploying Hermes Agent on Docker hosts exposed without authentication.

ThreatDown researchers describe a botnet named Carbonato that takes over Docker daemons exposed on the internet without authentication and installs Hermes Agent, an open-source AI agent framework, on them; BleepingComputer reported the findings on 24 September 2026 [1] [2]. Hermes Agent is the tool the attackers chose, not the subject of a reported flaw: the BleepingComputer article does not characterise the misuse as a weakness in the framework [1].

Background

Hermes Agent is an open-source agent framework from Nous Research that can run commands in an operating system terminal and act on instructions received through messaging channels. Its own documentation describes an approval system with three modes (smart, manual and off), an optional YOLO mode that skips approval prompts, and a set of commands that are blocked in every configuration [5].

Earlier 2026 reporting had already shown attackers running Hermes Agent in that unattended mode. Hunt.io described a July 2026 case in which an agent in YOLO mode, which removes prompts for human approval, ran privilege-escalation checks against hosts belonging to Thailand's Ministry of Finance [4]. Unit 42 reported on 31 July 2026 that a Chinese-speaking attacker configured Hermes in YOLO mode to take instructions from a Telegram channel while using DeepSeek as the reasoning engine [3].

Findings

According to BleepingComputer, Carbonato targets Docker hosts with an API exposed on port 2375 without authentication. The researchers found an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data, and the article reports that the botnet scans the networks attached to an infected host every five minutes for further exposed daemons [1].

The Hacker News reports that the botnet starts a privileged container to run commands on the underlying system, then installs Hermes Agent and overwrites the default SOUL.md persona file so that the agent acts as "GH0ST", described as a senior hacker, pentester and exploit developer. The persona names AI API keys and other credentials as the priority [2].

BleepingComputer states that the agent interprets a task, writes terminal commands, reads the output and decides what to do next, then returns its report to a Telegram chat. The data it is instructed to collect includes AI API keys, SSH credentials and access tokens [1]. The researchers could not attribute Carbonato to a known threat cluster and point to Costa Rica as a possible location of the operator [1].

Implications for people who run agents locally

The Carbonato entry point is an exposed Docker daemon, not a weakness in Hermes Agent, so the people at risk in this report are those who publish a Docker API without authentication. The sources fetched do not say whether any victim was a personal Mac, and the persistence methods reported (cron jobs and watchdog scripts) are Linux mechanisms [1] [2].

The reports do show what an agent with a terminal can do once someone controls its instructions: it collects credentials and reports back through an ordinary messaging service. The same capability is available to its legitimate owner, which is why the framework's documentation treats approvals, container isolation and key storage as configuration choices the operator must make [5].

Recommendations

  1. Never publish a Docker API on port 2375 without authentication. The researchers' advice is to enforce Docker daemon authentication, disable remote API access when it is not needed and segment networks to limit lateral movement [2].
  2. Keep Hermes Agent approvals on. The documentation lists smart as the default mode and manual as the mode that always asks for dangerous commands; off disables all approval checks [5].
  3. Run the agent in a container backend with the resource limits the documentation describes, and run it as a non-root user [5].
  4. Use explicit allowlists for the messaging gateway, and avoid the allow-all setting [5].
  5. Keep API keys in the agent's .env file with permissions restricted to the owner (chmod 600), as the documentation advises, and rotate any key that an agent host may have exposed [5].
  6. Keep Hermes Agent updated, and review its logs in the ~/.hermes/logs directory [5].

Relevance to FireAI

FireAI is a firewall for one Mac. It identifies an app by its code signature or path, shows the connections that app opens, and applies per-app rules to them. A Mac that runs Hermes Agent appears in FireAI as the interpreter that starts it, usually Python, so a rule applies to everything that interpreter runs. A rule that allows only the model provider's domain, with a block for every other destination, is the control that limits where such an agent may send data; the Activity page shows the destinations it contacted.

FireAI does not protect servers, does not scan for or close an exposed Docker port, does not manage Docker or any container, and does not inspect the instructions given to an agent or the contents of encrypted connections. It cannot stop an agent from reading or deleting local files. A Telegram connection that the user has allowed would not be questioned.

Limitations

The Carbonato findings are those of ThreatDown as relayed by BleepingComputer and The Hacker News; neither article, as fetched, states how many hosts were compromised. The two articles differ slightly in what they emphasise, and the exposure dates in the reporting were not reconciled here. The Hunt.io and Unit 42 cases are separate operations by different actors and are cited only to show that unattended Hermes Agent use by attackers was reported earlier in 2026 [3] [4].

The hardening steps come from Hermes Agent's own documentation, not from an independent audit, and this item does not test whether they stop the behaviour described in the botnet reports. The documentation also states that dangerous-command approval is skipped in sandboxed backends because the container boundary provides isolation [5].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. BleepingComputer, 24 September 2026: New Carbonato malware uses AI agents to hijack exposed Docker hosts
  2. The Hacker News, September 2026: Carbonato botnet compromises Docker hosts to deploy Telegram-controlled Hermes AI agent
  3. BleepingComputer, 31 July 2026: Hacker uses DeepSeek AI to autonomously attack vulnerable servers
  4. Hunt.io, 23 July 2026: Thailand Ministry of Finance targeted with Hermes AI agent running unattended
  5. Hermes Agent documentation: Security