CyberSecurity News
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
AI summary
Cybersecurity researchers have identified a new botnet malware known as Carbonato, which targets vulnerable Docker daemons. The malware deploys an artificial intelligence agent framework called Hermes Agent, which is an open-source tool. After installation, the malware overwrites a specific file in the framework to direct its actions. The overwritten file contains a prompt that instructs the agent to execute tasks received through a specific channel. The tasks are controlled remotely, utilizing the Telegram messaging platform. The Hermes Agent framework is installed unchanged, aside from the modified file that allows for remote task execution.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

