Here's a thing that didn't exist a couple years ago: a criminal operation running its own AI infrastructure, powered entirely by API keys stolen from small orgs and developers.
ThreatDown published their analysis of Carbonato this week, a botnet that targets servers running Docker daemons with unauthenticated access on port 2375. It's not new — the operation has been running since at least 2024 — but the recent report reveals something that changes the conversation: the attacker's primary objective isn't ransomware, isn't DDoS capacity, isn't crypto mining. It's stealing AI API keys to fund their own LLM gateway.
And the tool they're using to do it is an open-source AI agent framework that your own developers might be running right now.
What Carbonato actually does
Port 2375 is the Docker daemon API. It lets you issue commands to Docker remotely. It should never be publicly reachable without authentication — but Docker's default configuration doesn't enable TLS authentication, and tutorials all over the internet show people how to expose it for convenience. Thousands of hosts still have it open.
When Carbonato finds one, it doesn't install traditional malware. It uses the Docker API itself to spin up a privileged container with the host filesystem mounted, drops an SSH reverse tunnel for persistence, and then installs Hermes Agent — an open-source AI agent framework from Nous Research, MIT licensed, developed for entirely legitimate purposes. The attackers don't modify the framework. They just overwrite the 39-line SOUL.md persona file that tells the agent what it is. New persona: collect credentials, execute tasks from Telegram, maintain access.
From that point, the Hermes Agent is running autonomously on your server, receiving instructions from an attacker-controlled Telegram channel and responding with what it finds. It hunts for AI API keys — OpenAI, Anthropic, Cohere, Mistral — plus SSH credentials, database tokens, access keys. Those get sent back and fed into the attackers' own LLM gateway. The criminals are literally running a shared AI service at your expense.
What ThreatDown found in the attackers' own registry
Here's the part of this story that's actually remarkable: ThreatDown stumbled on the attackers' own container registry sitting unauthenticated on the internet. In a single day of passive collection, they grabbed 4.3 GB of the operation's toolchain: 59 repositories, 234 tags, 605 file blobs. The configuration history exposed the command-and-control addresses, the Telegram bot tokens, and the shared password for the attackers' own AI gateway.
The attackers misconfigured their own infrastructure the exact same way they exploit everyone else's.
This is worth sitting with for a second. A group sophisticated enough to build an AI-agent-powered botnet, integrate an open-source framework, run a multi-machine Telegram-operated command structure — they left their registry open because it was convenient. Misconfiguration isn't a beginner mistake. It's a universal one.
Why small orgs are the target
Carbonato is not going after enterprise infrastructure. Enterprise environments have network perimeters, port scanning detection, and secrets management systems. Your AI API key probably doesn't live in Vault. It lives in a .env file in a directory that your Docker Compose mounts as a volume, and that your AI agent framework reads at startup.
The self-hosted AI stack that a lot of small orgs have built over the past year — Ollama, Open WebUI, n8n, LangFuse, anything running in Docker on a VPS — that stack has real AI API keys in it. Keys with real billing attached. And many of those deployments trace back to a tutorial, a GitHub repo someone forked, a Compose file someone copied, where port 2375 or equivalent was exposed for simplicity.
The economic logic here is direct. Running a decent LLM gateway costs real money. A credentialed OpenAI API key at your 10-person NGO might have $500/month in capacity sitting on it. A team of 20 developers might have several keys across different tools. Enough compromised hosts and the attackers are running frontier AI for free.
How to check your own setup
Port 2375 scan: If you have any servers running Docker — a VPS, a cloud VM, a self-hosted stack — scan them. The quickest check: curl -s http://your-server-ip:2375/version. If you get a JSON response back with Docker version information, your daemon is unauthenticated and reachable. That's the full exploit surface right there.
Audit your Docker Compose files for network exposure: Any ports: entry that maps to 0.0.0.0 (or just port:port without a bind address) exposes that port to the public internet if your firewall doesn't block it. Docker famously bypasses UFW and some iptables rules, so firewall exceptions you think you set may not be protecting you.
Rotate API keys that are in any Docker environment: If you've had AI API keys configured in any self-hosted AI tool, assume they may have been read. OpenAI, Anthropic, Cohere, Mistral — all of them let you create new keys and revoke old ones in minutes. Do that now and monitor usage on the new key for the first week.
Put API keys in a secrets manager, not environment files: Docker Swarm secrets, AWS Secrets Manager, HashiCorp Vault, even a simple .env file that is explicitly excluded from version control and not bind-mounted as a readable volume — any of those is better than a key sitting in a Compose file in your home directory. This is hygiene that's gotten more urgent now that AI API keys have direct dollar value to an adversary.
Check for unexpected Hermes Agent installations: If you're already worried a host may be compromised, look for the Hermes Agent binary in running containers or on the host filesystem. Because the attackers use the legitimate, unmodified framework, detection tools may not flag it. The thing to look for is an unexpected Python environment with Hermes Agent installed, and outbound connections to Telegram's API endpoints.
The broader shift
What Carbonato signals is a change in what attackers want. For years the value in a compromised server was compute: mine crypto, run bots, launch DDoS. That's still happening. But now a fresh OpenAI API key has a street value you can assign. Stolen credentials aren't just for identity fraud anymore — they're operational inputs for running AI infrastructure.
That changes the threat calculus for any team using AI tools. Before, a compromised server meant downtime and cleanup. Now it also means someone may have been billing your AI budget for months before you noticed.
The teams most exposed are the ones who built self-hosted AI stacks quickly, by copying tutorials, without going back to harden the network config afterward. That's most of them. The fix isn't complicated — port 2375 closed, API keys rotated, secrets out of env files — but it requires someone to actually do it.
We spend a lot of time doing exactly this with teams: not the part where you deploy the AI tool, but the part where you make sure the AI tool isn't handing credentials to someone on Telegram. Let us know if that's a useful conversation.