AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO hijacks exposed Docker hosts, installs an AI agent, and steals LLM API keys to fund its gateway.
ThreatDown uncovered the CARBONATO Docker botnet after an internet-exposed container registry leaked its toolchain, including 59 repositories and 4.3 GB of images gathered in one day. Active since at least October 2024, it finds Docker daemons accepting unauthenticated connections on port 2375, starts a privileged container, and opens a reverse SSH tunnel to a relay in Costa Rica while reporting over Telegram. Persistence uses cron, systemd, rc.local, and OpenRC, with the container masquerading as systemd-resolved. It then installs Nous Research’s unmodified Hermes Agent, overwrites SOUL.md so the GH0ST persona prioritizes stealing API keys from 14 LLM providers, and uses those keys to fund its own gateway while worming to other exposed hosts.