started · updated
CARBONATO botnet uses autonomous AI agents for command-and-control
Researchers at ThreatDown have identified CARBONATO, a novel botnet that utilizes an autonomous AI agent as its command-and-control (C2) engine. Unlike traditional botnets that rely on static, hardcoded scripts, CARBONATO uses the open-source Hermes Agent framework to reason through its environment and adapt to the specific configurations of compromised hosts.
The botnet typically gains access through Docker services that are exposed to the internet without authentication. Once inside, it launches a privileged container to gain host access and establish persistence. The attackers overwrite the framework’s persona file with specific instructions, renaming the agent ‘GH0ST’. This allows operators to send tasks via Telegram, which an LLM gateway then interprets to generate and execute terminal commands on the victim server.
A unique characteristic of CARBONATO is its focus on stealing AI API keys from providers such as OpenAI, Anthropic, and Google. These stolen credentials are reportedly used to fund the operators’ own LLM gateway. This self-funding mechanism and the use of autonomous reasoning for reconnaissance and exploitation represent a significant evolution in cyberattack methodology.
Entities
Carbonato · Hermes Agent · Nous Research · Telegram · ThreatDown