ThreatDown reports a botnet that compromises Docker hosts with unauthenticated APIs, installs the open-source Hermes Agent framework with a replaced persona file, and has the agent carry out tasks sent over Telegram, including collecting AI API keys and other credentials. ThreatDown recovered the operation's toolchain from an exposed registry, with images dating from October 2024 to August 2026, and describes the agent reading command output and deciding next steps in an operator-driven loop.
Why it matters
It shows an off-the-shelf agent framework used as a botnet implant, with AI API keys treated as a primary theft target.
Key facts
As stated in the sources, with where to find them.
- The exposed registry held 59 repositories, 234 image tags and 4.3 GB of image data.Findings table
- The agent’s prompt directs it to collect AI API keys from 14 providers ahead of SSH credentials and access tokens.Findings table
- Scripts, not the agent, spread the botnet by scanning attached networks for exposed Docker daemons. ThreatDown did not attribute it to a known cluster but assesses the operators as likely in Costa Rica.Article body; BleepingComputer
Findings that cite this record
Aug 27, 2025
Nov 5, 2025
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Jul 1, 2026
May 11, 2026
Aug 27, 2025