On September 22, 2026, ThreatDown described Carbonato, a botnet targeting Docker daemons exposed without authentication. Once inside, operators can launch a privileged container, install Hermes Agent and use it to execute tasks delivered through Telegram.
What the Carbonato research establishes
ThreatDown traced the operation by analyzing an unauthenticated Docker registry and passively collecting 4.3 GB of related images and files. Its research describes two connected activities: a counterfeit cryptocurrency-wallet operation and a botnet targeting Docker daemons exposed on port 2375. The published evidence describes spread to reachable hosts and credential collection, with AI API keys as a priority; observed behaviour may vary by host.
The Docker daemon's role
The initial foothold is not an Hermes Agent flaw but an unauthenticated Docker API, often exposed on port 2375. A management API reachable from the network lets an attacker request a container that crosses the expected isolation boundary.
Hermes Agent repurposed
Hermes Agent is a legitimate open-source project. Carbonato installs it and replaces its configuration so it becomes a Telegram-controlled execution console. This can make detection harder than a completely unknown binary, but it does not make the upstream project malware.
Contain the host and rotate secrets
Isolate a suspicious host, close the public Docker API and search for unexpected containers, images, SSH keys and processes. ThreatDown also recommends looking for a SOUL.md file containing “GH0ST,” the CARBONATO_API_KEY variable, the /usr/local/bin/.docker-network-monitor watchdog and a process disguised as [kworker/u2:0]. After preserving evidence needed for analysis, revoke and replace API keys, cloud tokens and secrets that were accessible from the host; check neighbouring systems as well. For a separate example of secrets exposed in an incident, see our article on secrets related to the JetBrains-Cadence incident.
How Soclyde fits
Soclyde does not secure the Docker daemon or replace host investigation. Its local-first encrypted vault helps teams keep distinct passwords for their accounts. It does not manage or automatically revoke AI API keys; those must be inventoried, revoked and rotated with the relevant providers.
Key takeaway
Carbonato shows the concrete risk of a public Docker API: a legitimate framework becomes an operator tool after compromise. Close the exposure, inspect containers and rotate affected secrets. See the secure password generator or contact Soclyde.



