Hermes Agent is an MIT-licensed, open-source AI agent framework developed by Nous Research. It has been abused by the CARBONATO Docker botnet on compromised Linux hosts. CARBONATO installs the framework and replaces its default agent persona with a malicious configuration named GH0ST, while leaving the framework itself otherwise unchanged. In this deployment, Hermes Agent receives operator tasks through Telegram, submits task context to an attacker-controlled LLM service, executes generated terminal commands on the compromised host, and returns results to the operators. The malicious configuration prioritizes collection and exfiltration of AI-service API keys, SSH credentials, access tokens, and database-related data, and directs the agent to support persistence. CARBONATO reaches hosts by exploiting Docker daemon APIs exposed without authentication, then deploys Hermes Agent after obtaining host-level execution through privileged containers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
FOFA scans confirmed the instinct: over 647,000 n8n instances existed worldwide, more than 25,000 of them in China.
the actor had customized Hermes Agent with three red-teaming skills: fofa-cyberspace-search: a custom procedure template instructing DeepSeek to use the actor’s fofoapi.py script for internet asset enumeration
They targeted internet-exposed infrastructure by combining autonomous AI-driven enumeration and automated exploitation with the automated and manual exploitation of seven vulnerabilities.
« ...la faille de sécurité de l’extension Chrome d’Adobe Acrobat, HermeticReader, expose des données sensibles de WhatsApp Web dès la simple visite d’une page malveillante. Ces pages web ressemblent à n’importe quelle autre page, mais lorsque vous en visitez une, le piège se déclenche... »
“The model interprets the task, writes terminal commands, reads the output, and decides what to do next... The agent runs those commands on the victim.”
The model interprets the task, writes terminal commands, reads the output, and decides what to do next. The agent runs those commands on the victim.
Hermes Agent provided orchestration (terminal access, Telegram-based command and control, and the skills system)
“Hermes handles task commands received through Telegram... running commands, and sending back the results.”
Hermes Agent gives the operators a Telegram interface to send tasks to compromised hosts... The agent runs those commands on the victim and returns its report to the Telegram chat.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AI-agent framework weaponized by the Carbonato operators to interpret Telegram-delivered tasks, generate and execute terminal commands on compromised Docker hosts, collect credentials and tokens, and return results to an operator-controlled Telegram chat.
A legitimate open-source agent framework weaponized by CARBONATO operators. The framework is installed unchanged, but its SOUL.md persona is replaced to direct Telegram-controlled command execution, persistence, credential theft, and AI API-key exfiltration through the operation’s LLM gateway.
A legitimate open-source agent framework that CARBONATO installs unchanged but weaponizes by overwriting its SOUL.md persona with malicious instructions. In the operation, it receives Telegram tasking, passes tasking and the malicious persona to an LLM gateway, executes generated terminal commands on compromised hosts, and returns results to the operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.