Cybersecurity researchers have published details of a newly identified botnet tracked as Carbonato. The malware is designed to find Docker daemons that are exposed to the internet and compromise them, according to the report.

Once inside a host, Carbonato installs Hermes Agent, an open-source AI agent framework. The implant is said to install the framework without modification, then uses it for subsequent malicious activity. The botnet's command-and-control appears to rely on Telegram.

Because the report is a single source, these findings have not been independently confirmed. Still, the campaign highlights how AI agent tooling can be repurposed in attacks against misconfigured cloud infrastructure.