NewA botnet shipped no malware at all — the payload was 39 lines of English
Evren
← Blog

The payload was 39 lines of English

A botnet built around an off-the-shelf AI agent shipped no malicious binary at all. What that changes about detection — and what it tells us attackers now value most on a host.

Gaurav NagarCo-founder6 min read

In August, researchers at ThreatDown found an unauthenticated Docker registry that had been sitting open since May. Inside was a botnet they named CARBONATO: it spreads worm-like across hosts with exposed Docker daemons, runs in a privileged container with the host filesystem mounted, and establishes persistence through cron, systemd timers and immutable file locks.

None of that is new. Exposed Docker daemons are a decade-old misconfiguration, and worms have been doing the rest since before any of us were writing policy engines.

The part worth your attention is what was waiting on the other side.

No binary to catch

The operators did not write malware. They took Hermes Agent — an MIT-licensed, open-source agent framework — and shipped it unmodified. The entire malicious payload is a 39-line prompt file called SOUL.md.

It tells the agent to maintain persistence, take operator tasks over Telegram, and execute whatever is asked. The agent then runs an interactive loop: read the task, write a terminal command, read the output, decide what to do next.

There is nothing to sign, nothing to diff, and no binary that a hash list will ever catch. The framework is software you might legitimately install.

This is the shift that matters. We have spent thirty years building detection around artifacts — files with hashes, binaries with signatures, libraries whose contents can be compared against a known-good copy. The thing that made this host hostile was a text file written in English, and the executable was something a developer could plausibly have chosen on purpose.

Attackers published their own price list

The prompt also specifies what to steal, in order. It prioritises API keys from AI providers — above SSH credentials, access tokens and databases — and directs the agent to write every key, password and token in plaintext to /root/.hermes/loot/.

Read that as a market signal rather than an implementation detail. Someone who compromises hosts for a living, and who gets to pick what to carry out, now ranks model-provider credentials above the database. That ordering did not exist two years ago.

What this is not

It would be easy — and wrong — to call this an AI-powered attack and move on. The AI is not in any of the load-bearing positions. Initial access is the Docker misconfiguration. Spread is a script on a five-minute cron. Persistence is established before the agent even starts. The researchers say plainly that the agent “has no role in the final phase.”

Swap the agent for a conventional reverse shell and the campaign still works. The operator just has to type more.

So this is not a new class of attack. It is attackers adopting agents as tooling, which is both less alarming and more instructive than the headline version — because the same adoption is happening inside your estate, on purpose, with your approval.

The uncomfortable symmetry

Hold CARBONATO next to the SRE agent your platform team deployed last quarter. Both are an LLM in an interactive command loop. Both run with real privilege on a host. Both write their own next command based on what they just read. Both were installed deliberately by someone with credentials.

The difference is intent. And intent is not a control.

You cannot configure your way out of this one. The misconfigured Docker daemon is older than the threat and there will always be one. What you can decide is what any agent — yours or someone else’s — is actually able to do once it is already inside: which binaries it may execute, which paths it may read, which syscalls it may make, and whether any of it is written somewhere the agent cannot quietly edit.

That is a boundary question, not a detection question. Detection told ThreatDown what had happened. It ran for ten months first.