Research
ThreatDown says the CARBONATO botnet installs an unmodified Hermes Agent and targets AI API keys first.
2026-09-28 · that day's edition
ThreatDown says the Docker-targeting botnet installs an unmodified open-source agent framework and prioritises stealing AI API keys over other credentials.
What this rests on
-
ThreatDown published its report on CARBONATO on September 22, 2026.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
AI API keys ahead of SSH credentials, access tokens, databases, and other credentials
-
The botnet installs Hermes Agent, an MIT-licensed open-source framework from Nous Research, unmodified, then overwrites its persona file with instructions to maintain persistence and respond to Telegram commands.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
AI API keys ahead of SSH credentials, access tokens, databases, and other credentials
-
The persona file directs the agent to prioritize stealing AI API keys from 14 providers ahead of SSH credentials, access tokens and databases.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
AI API keys ahead of SSH credentials, access tokens, databases, and other credentials
-
It spreads by scanning for Docker hosts with an API exposed on port 2375 without authentication.
CARBONATO: a botnet built around an AI agent · ThreatDown (Malwarebytes) · 2026-09-22
AI API keys ahead of SSH credentials, access tokens, databases, and other credentials
We checked every sentence above against its source by opening it. Nothing appears
on this site that we have not opened and linked.
Filed under
Also that day