Carbonate Campaign exploits Docker exposed and deploys Hermes Agent controlled by Telegram

Author: Published 5 min de lectura 9 reading

The images in this article were generated with artificial intelligence. How we publish

Cybersecurity researchers have revealed an active campaign using a new, nicknamed button Carbonate to engage servers with Docker exposed without authentication and deploy an open source artificial intelligence agent called Hermes Agent. According to the technical report that the firms that investigated the operation disseminated, the main impact is that the attackers transform committed hosts into remote controlled nodes that obey instructions sent by Telegram and prioritize the search for APIs keys of IA and credentials.

The facts confirmed by the researchers are as follows: Carbonate exploits Docker demons accessible through the network through the unsafe port 2375, launches containers with privileges over the affected hosts to execute commands in the underlying system, sets persistence through programmed tasks and watch-dog scripts, and sets up an inverse SSH tunnel towards an external relay. In each committed machine, Hermes Agent is installed without changing the binary, but it overwrites its SOUL.md personality file with a prompt that orders the agent to act as a "senior operator" without ethical restrictions and to respond to orders received by Telegram. In addition, the operation has a worm-like capacity: each host scans adjacent networks every five minutes to locate new Docker demons without authentication and spread. These findings were reportedly identified from data exposed in a Docker record without authentication that was public since May 2026.

Carbonate Campaign exploits Docker exposed and deploys Hermes Agent controlled by Telegram
Image generated with IA.

Technically, the engagement chain described combines surface explosion and automation techniques. The initial vector is access to the Docker demon socket (exposed for example in port 2375), which allows the attacker to create privileged containers. Within these containers, a script is run that lifts an inverse SSH tunnel into a controlled relay (researchers note infrastructure in Costa Rica as an intermediate point), installs an SSH server with the operator's public key for persistent access and notifies the new node through Telegram. Hermes Agent, configured with the malicious prompt, receives tasks via Telegram, sends those instructions to a LLM model or to a LLM gateway, and converts the model outputs into terminal commands that the container runs into the compromised host. The attackers would also have crossed or included in the record data from another campaign - crypto-troped applications - suggesting the sharing of infrastructure for multiple operations.

What is confirmed: the basic mechanics of infection (Docker exposed → privileged container → persistence → deployment of Hermes Agent) and the use of Telegram as a control channel. The documented technical evidence includes the inverse SSH tunnel artifacts, cron jobs and watchdogs that relaunch the implant if it is removed, and the modification of the agent's SOUL.md file to force offensive behavior. It is also confirmed that the operation prioritizes the collection of API keys and credentials.

What is estimate or not yet verified: the complete attribution of the actor operating Carbonate. The researchers point to signs of language, time zones and infrastructure that point to operators located in Costa Rica, but there is no public and conclusive link to a known group. The total scope of Internet infections (number of machines engaged) and the complete list of targets affected are also not fully verified.

This case fits a greater trend: operators that combine IA agents with traditional implants to automate the attack cycle. Previous reports mention uses of Hermes Agent and related tools in campaigns that automate recognition, exploitation and exfiltration without constant human supervision. In addition, implants that consult multiple LLM providers to decide post-commitment actions have been identified, demonstrating the increased role of language models in the malicious chain of command.

For organizations and system managers, the implications are concrete and urgent. A Docker demon exposed without authentication is equivalent to giving remote root access: it allows you to run privileged containers and compromise the host. The combination with IA agents adds speed, creativity and persistence to malicious campaigns, because the attacker can orchestrate multiple tasks of collecting secrets, latency and pivoting with little human intervention.

Immediate practical actions: first, identify and close any Docker daemon exposed to public networks. Do not expose the demon socket to the network; entrust it to localhost or use TLS and authentication. For public guidelines on how to protect Docker Demon, review Docker's official documentation and community good practices as the OWASP guide for Docker: https: / / docs.docker.com / engine / security / and https: / / cheatsheetseries.owasp.org / cheatsheets / Docker _ Security _ Cheat _ Sheet.html.

Second, investigate engagement indicators in Docker hosts: look for containers launched with the --privileged flag, presence of newly installed SSH servers, autossh processes or unusual outgoing SSH connections (reverse tunnels), and entry in cron or watchdog scripts that relaunch binaries. Audit SSH authorizations (authorised _ keys) and review container images and records to identify new loads or unsigned images.

Third, round and audit keys and credentials that could have been exfiltered, especially IA APIs keys and service tokens. Configure alerts for unusual activity to APIs (Telegram) or to LLM providers and limit, by policy, access to sensitive key services.

Carbonate Campaign exploits Docker exposed and deploys Hermes Agent controlled by Telegram
Image generated with IA.

Fourth, implement network controls: segmentation, access control lists that prevent production hosts from freely contacting the Internet or external relays, outbound traffic inspection and blocking of ports that are not necessary (like 2375). Consider signed image policies and image scanning in private records with R / O. authentication

Finally, if you suspect engagement, preserve evidence (logs, container images, memory processes) and consider controlled disconnection to avoid spread. Notify incident response teams and, where appropriate, the competent authorities. Automation with IA reduces the viable response window: containment must be faster and accompanied by resilience and secret rotation measures.

This case again stresses that container security and the protection of IA credentials are now critical vectors. Protecting Docker Demon, ensuring private records and auditing key use are concrete measures that reduce the risk that legitimate automation tools - such as Hermes Agent - will be reused for malicious operations.

Coverage

Related

More news on the same subject.