Malware

Carbonato Malware Leverages AI Agents to Hijack Exposed Docker Hosts via Unauthenticated API

September 25, 2026 08:00 · 6 min read
Carbonato Malware Leverages AI Agents to Hijack Exposed Docker Hosts via Unauthenticated API

Carbonato Malware Targets Unsecured Docker Daemons

A newly identified botnet malware named Carbonato is actively compromising Docker hosts that expose their daemon API on port 2375 without authentication. Discovered by researchers at enterprise security firm ThreatDown, the malware was found in an unauthenticated Docker registry containing nearly 60 repositories and 4.3 GB of image data. Operational evidence collected by ThreatDown spans from October 2024 to August 2026, indicating a prolonged and active campaign.

Carbonato exhibits worm-like behavior, scanning for and infecting other exposed Docker daemons every five minutes. Upon gaining access, the malware instructs the Docker daemon to launch a privileged container, granting it full host-level access. This initial compromise enables the installation of persistence mechanisms, including cron jobs, systemd timers, rc.local entries, and OpenRC hooks, ensuring survival across reboots.

Hermes Agent AI Framework Deployed as 'GH0ST'

A distinctive feature of the Carbonato attack is the deployment of the Hermes Agent AI framework on compromised hosts. The malware installs an AI agent named "GH0ST," which overwrites the default 'SOUL.md' persona file with malicious instructions. Once activated, the GH0ST agent operates within an interactive command loop: it interprets tasks received via Telegram, generates appropriate terminal commands, executes them on the victim system, reads the output, and determines the next action.

According to ThreatDown researchers, "The model interprets the task, writes terminal commands, reads the output, and decides what to do next. The agent runs those commands on the victim and returns its report to the Telegram chat that also receives deployment reports."

Through this AI-driven loop, attackers can remotely collect sensitive data such as AI API keys, SSH credentials, and access tokens, execute arbitrary commands, and exfiltrate results—all orchestrated via Telegram communications.

Persistence, Spread, and Attribution Clues

Carbonato’s propagation mechanism relies on scripts that continuously scan networks attached to compromised hosts. Each newly infected system pulls the implant from the same Docker registry, launches a privileged container, and repeats the persistence and scanning cycle. This self-replicating behavior enables rapid expansion across vulnerable infrastructure.

While ThreatDown could not link Carbonato to any known threat actor or cybercrime group, various indicators suggest a possible operational base in Costa Rica. The malware’s infrastructure includes reverse SSH tunnels pointing to AS262145, a network associated with hosting providers in that region.

Indicators of Compromise and Mitigation Guidance

Organizations can detect potential Carbonato infections by monitoring for specific indicators: the presence of a GH0ST persona file, the environment variable CARBONATO_API_KEY, unexpected outbound Telegram traffic, and reverse SSH connections to AS262145.

To prevent infection, ThreatDown recommends securing Docker daemon APIs by restricting network exposure and enforcing authentication on Docker registries. Disabling public access to port 2375 and implementing strict registry access controls are critical steps in mitigating this threat.

This campaign coincides with a broader trend of AI-enabled malware, including related threats like ClosedQuorum targeting Windows systems and RatHat affecting Android devices. The use of AI frameworks such as Hermes Agent in offensive operations underscores the growing convergence of artificial intelligence and cybercrime, necessitating updated defensive strategies capable of detecting and responding to machine-speed attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free