Carbonato botnet hijacks exposed Docker hosts with AI agent
ThreatDown says Carbonato infects unauthenticated Docker APIs, persists, spreads, and uses a Telegram-steered Hermes agent to steal credentials.
Malwarebytes ThreatDown researchers described Carbonato, a worm-like botnet that hijacks Docker hosts exposing an unauthenticated API on port 2375. It starts a privileged container, opens a reverse SSH tunnel, adds operator SSH access, and persists through cron, systemd timers, rc.local, and OpenRC; Security Affairs adds that the container masquerades as systemd-resolved and that the tunnel reaches a relay in Costa Rica. Operators install Hermes Agent under a GH0ST persona that receives Telegram tasks, collects AI API keys, SSH credentials, and tokens, runs commands, and returns results. Sources differ on details: Security Affairs says the agent is Nous Research’s unmodified Hermes steered by a 39-line SOUL.md to steal keys from 14 LLM providers and fund the operators’ gateway, while Cyber Security News also lists database secrets and the others do not describe gateway funding. Scripts, not the agent, scan attached or adjacent /24 networks every five minutes and spread the implant. Researchers found an exposed registry of 59 repositories—nearly 60 in one account—and about 4.3 GB of images; reports disagree on whether the images were collected in one day or cover activity from October 2024 through August 2026, and Costa Rica remains only an unconfirmed lead.
- Carbonato (also styled CARBONATO) compromises Docker hosts exposing an unauthenticated API on port 2375 by launching a privileged container.
- It opens a reverse SSH tunnel, installs an SSH server with the operators’ key, and persists via cron, systemd timers, rc.local, and OpenRC; one report says the container masquerades as systemd-resolved.
- The implant installs Hermes Agent—described by two sources as unmodified, and by one as Nous Research’s Hermes Agent—under a GH0ST persona steered by Telegram tasks.
- The persona collects AI API keys, SSH credentials, and tokens; one source also lists database secrets, and another says a 39-line SOUL.md targets keys from 14 LLM providers to fund the operators’ gateway.
- Worm scripts, not the agent, scan attached or adjacent /24 networks every five minutes and redeploy the implant.
- An exposed registry held 59 repositories (one outlet said nearly 60) and about 4.3 GB of images tied to activity from October 2024 to August 2026.
- Sources disagree on whether those images were gathered in one day or span that full period; Costa Rica is a possible operator or relay location, and attribution is unconfirmed.
Coverage timelineoldest first · each row is one article
- · 2d agoNew Carbonato malware uses AI agents to hijack exposed Docker hosts
BleepingComputer· 76
Carbonato botnet hijacks exposed Docker hosts, installs Hermes Agent, and spreads by scanning for more daemons.
- · 1d agoAI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
Security Affairs· 76
CARBONATO hijacks exposed Docker hosts, installs an AI agent, and steals LLM API keys to fund its gateway.
- · 1d agoResearchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
Cyber Security News· 74