The Malware Is a Note

October 3, 2026 · SPR{K}3 Research

A new botnet called Carbonato is spreading across the internet. The interesting thing isn't what it does. It's what it is.

ThreatDown found it on September 23. The Hacker News and Dark Reading picked it up five days later. The entry point is old-fashioned. Attackers scan the public internet for computers running Docker with the front door left open — a known misconfiguration on TCP port 2375 that has fed cryptomining botnets for years. One request, and they're inside.

That part isn't new. What they install is.

What they install

Instead of writing their own malware, the attackers download a free, legal AI assistant from the internet. Hermes Agent, from Nous Research. MIT-licensed. On Docker Hub. Exactly the kind of thing a developer might use.

Then they overwrite one file inside it — a 39-line text document called SOUL.md — with their own instructions. That file is the entire malware.

The instructions, roughly, say:

The AI assistant obediently does all of it.

Why that matters

Nothing is technically broken. The AI framework is working exactly as its maintainers designed it. The binary is unmodified. The dependencies are clean. The traffic to Telegram looks like every other legitimate bot on the internet.

The malicious thing on the disk is a markdown file.

This breaks a lot of assumptions. Antivirus looks for bad binaries — there aren't any. Dependency scanners look for compromised packages — the package is fine. Network defenders look for suspicious command-and-control servers — the server is Telegram, the same one millions of harmless apps already use. There is no CVE to patch, because nothing is vulnerable in the traditional sense.

The attacker didn't write a program. They wrote a note.

The target has shifted

The order of what the agent steals is worth paying attention to. For most of malware history, credentials were credentials — passwords, SSH keys, bank logins, roughly in that order. Carbonato puts AI service credentials at the top of the list, above everything else.

That's a signal. The resale market for a stolen OpenAI or Anthropic API key is now active enough that operators are prioritizing it. The secondary payload — a Monero miner — looks like cover. The main business is AI accounts.

It spreads by itself

The agent is told to scan nearby networks every five minutes for more vulnerable Docker hosts and repeat the install when it finds one. That's a worm. But the operator didn't have to write worm code. They described a worm in plain English, and the agent did the rest.

How they got caught

The attackers made one mistake. They left their own storage server open to the public with no password. Researchers walked in and found 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of payloads, with activity logs going back to October 2024. The folder names — gh0st/, fsociety/, netd-svc — told their own story.

The operator's Telegram handle is Carbo506. The +506 country code is Costa Rica. The reverse-SSH tunnel terminates in a Costa Rican autonomous system. The timestamps line up with Costa Rican time. ThreatDown stopped short of naming anyone. The shape of the evidence speaks.

Why this is new

Most AI-security stories so far have been about tricking a well-behaved AI into misbehaving — prompt injection hidden in a web page, jailbreaks disguised as roleplay, elaborate ways to get a safety classifier to look the other way.

Carbonato is the other direction. The attacker brought their own AI. There is no safety classifier because there is no vendor in the loop. The operator writes the AI's instructions themselves, in a single text file, on a machine they already control.

That means anyone who can write a convincing paragraph can now build malware. You don't need to be a programmer. You need to be able to describe what you want.

What a defender actually sees

The individual actions Carbonato takes are each small. A new file written. An outbound connection to Telegram. A read of a credentials file. A scan of a nearby subnet. On their own, each of these is normal somewhere.

Together, in the same minute, on the same machine, they aren't. A workload host that suddenly starts talking to Telegram, reading every AI config file it can find, and scanning its neighbors — that's a sequence with no innocent explanation. The implant isn't a file to find. It's a pattern of behavior to recognize.

The takeaway

The next generation of malware will look exactly like the AI agents we're already running in production. The way to see it is to watch what the agents actually do.


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.