# Carbonato AI Agent on Exposed Docker Hosts

> Carbonato uses exposed Docker hosts to run an AI agent and steal API keys. Use this hardening checklist before an agent touches business systems.

**URL:** https://www.ciptadusa.com/blog/carbonato-ai-agent-docker-hosts-security  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-09-29  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-09/daily-appsec-20260929-040835.jpg  

## Article

# Carbonato puts an AI agent on hacked Docker hosts

Carbonato Botnet uses exposed Docker hosts to run Hermes Agent, receive commands through Telegram, and steal AI API keys. Dark Reading's September 28, 2026 report warns teams building AI agent backends: a misconfigured container can become an attacker's execution point instead of an automation foundation.

## Summary

Dark Reading reported that Carbonato uses the open source Hermes Agent AI framework to execute commands through Telegram. The botnet also searches compromised Docker hosts for AI API keys.

The main risk is not the AI label. It is the combination of exposed Docker services, readable credentials, and an agent that can execute commands. Together, these conditions can turn an initial compromise into access to other services.

## Background

Dark Reading's RSS report says Carbonato targets exposed Docker hosts. After gaining access, the botnet uses an agent to receive Telegram instructions and run commands. It also looks for AI API credentials that can support model usage or further access.

This does not show that every Hermes Agent installation is malicious. The issue is the execution context. An open source framework running with broad permissions inherits the risks of its host, tokens, network, and available tools.

Teams managing AI automation Indonesia should treat an agent as a privileged workload. It is not only a chatbot when it can read files, call commands, or access APIs.

## AI agent backend development needs access boundaries

What is the first check? Remove Docker API exposure from the public internet. If outside access is required, put the service behind a private network, strong authentication, and a firewall that limits source addresses.

The second check is secrets. Search images, volumes, environment variables, and logs for AI API keys, cloud tokens, database credentials, and configuration files. Move secrets into a secret manager. Limit token scope and rotate any token that was present on an exposed host.

The third check is agent permission. Use a read-only filesystem when possible. Remove unnecessary Linux capabilities. Isolate the network so the agent cannot reach every internal system. Record each command and tool call.

The Carbonato incident also shows why pengembangan MCP server needs security design from the start. Tools should allow only required operations. Validate parameters, block sensitive paths, set timeouts, and require human approval for destructive actions.

## What security teams should prioritize

Start with Docker, firewall, reverse proxy, and Telegram bot logs. Look for unusual outbound connections, new containers, image changes, root processes, and requests for files such as environment configuration or credential directories.

If a host was exposed and stored an API key, treat the token as compromised until proven otherwise. Revoke and reissue it. Check model usage and bills. Review cloud accounts, databases, and internal services reachable from that host.

When evaluating a vendor, ask more than which model it uses. Ask whether it runs agents in a sandbox, how it isolates tools, whether logs are available, and who approves production data access. The answers should be testable through configuration and failure scenarios.

## Implications

Carbonato is not a reason to avoid AI agents. It is a reason to place agents under controls as strict as other privileged workloads. Close Docker API exposure, rotate secrets, reduce container permissions, limit network access, and preserve logs before giving an agent access to business processes.

Sources: Dark Reading, "Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts," September 28, 2026, https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts. Technical reference: Docker security documentation, https://docs.docker.com/engine/security/.

If you need to assess an agent architecture or harden an AI integration, you can [talk with a team that builds AI agent backends and MCP servers](https://wa.me/6285792071380) about access boundaries and audit paths.

---

*Markdown version of https://www.ciptadusa.com/blog/carbonato-ai-agent-docker-hosts-security — generated for AI agents and LLM crawlers.*
