Research
ThreatDown says the CARBONATO botnet installs an unmodified Hermes Agent and targets AI API keys first.
2026-09-28 · that day's edition
ThreatDown says the Docker-targeting botnet installs an unmodified open-source agent framework and prioritises stealing AI API keys over other credentials.
Your reaction
One press adds one. We count a number for each notice and day, never who pressed it.
What this rests on
-
ThreatDown published its report on CARBONATO on September 22, 2026.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
CARBONATO report at threatdown.com/blog/carbonato, dated September 22, 2026
-
The botnet installs Hermes Agent, an MIT-licensed open-source framework from Nous Research, unmodified, then overwrites its persona file with instructions to maintain persistence and respond to Telegram commands.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
installs Hermes Agent, an MIT-licensed, open-source framework from Nous Research ... overwrites the agent’s SOUL.md persona file with the crew’s 39-line prompt. The framework already accepts Telegram tasks
-
The persona file directs the agent to prioritize stealing AI API keys from 14 providers ahead of SSH credentials, access tokens and databases.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
AI API keys are the absolute priority ... OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, One API
-
It spreads by scanning for Docker hosts with an API exposed on port 2375 without authentication.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
Docker daemons that accept unauthenticated connections on port 2375
We checked every sentence above against its source by opening it. Nothing appears
on this site that we have not opened and linked.
Filed under
Also that day