Carbonato Malware Leverages AI Agents to Hijack Exposed Docker Hosts

A sophisticated new botnet malware, dubbed Carbonato, has emerged, exhibiting alarming worm-like capabilities and a strategic reliance on advanced AI agents to compromise unsecured Docker hosts. Threat actors are exploiting Docker daemons with exposed APIs, often on port 2375 without any authentication, to infiltrate systems, install the potent Hermes Agent AI framework, and establish persistent control. Researchers at enterprise security firm ThreatDown have meticulously documented the malware’s operations, uncovering evidence spanning from October 2024 to August 2026 within an unauthenticated Docker registry. This discovery not only revealed the intricate workings of the Carbonato botnet but also highlighted a parallel campaign distributing fraudulent cryptocurrency wallet applications, underscoring the multifaceted nature of this threat.

The Anatomy of a Docker Host Compromise

Carbonato’s infection vector is deceptively simple yet highly effective. The malware actively scans networks for Docker daemons that have their API accessible without authentication. Upon identifying a vulnerable host, it connects to the exposed API and issues commands to the Docker daemon. A critical step in this process is the instruction to launch a privileged container. This elevated access grants Carbonato immediate and comprehensive control over the underlying host system.

Once initial access is secured, the malware initiates a multi-pronged approach to establish persistence and facilitate remote command and control. A reverse SSH tunnel is established, creating a covert channel back to the attackers. Simultaneously, an SSH server is installed on the compromised host, configured with the attackers’ specific SSH keys, ensuring their unfettered access. To solidify its presence, Carbonato deploys a range of persistence mechanisms, including the creation of cron jobs, systemd timers, rc.local entries, and OpenRC hooks. These automated tasks ensure that the malware can survive system reboots and maintain its foothold even if initial entry points are discovered and remediated.

The final step in the initial compromise phase involves the malware reporting its successful deployment. This communication is facilitated through Telegram, a messaging platform frequently utilized by malicious actors for command and control due to its perceived anonymity and ease of use. This reporting mechanism allows the operators to track their growing botnet and coordinate further malicious activities.

The Rise of AI in Cyber Warfare: The Hermes Agent Integration

A particularly concerning aspect of the Carbonato attack is its integration with the Hermes Agent AI framework. On compromised hosts, Carbonato deploys Hermes, assigning it the agent name "GH0ST." This agent is specifically instructed to overwrite the default "SOUL.md" persona file, a customization that likely tailors the AI’s behavior and capabilities to the specific objectives of the Carbonato operators.

New Carbonato malware uses AI agents to hijack exposed Docker hosts

The Hermes Agent has been a growing concern in the cybersecurity community, with its AI-driven capabilities being increasingly abused in sophisticated cyber operations. Earlier reports have detailed its use in automating attacks against vulnerable servers and facilitating large-scale financial fraud. For instance, cybersecurity firm Gambit documented a significant card-skimming operation where malicious AI agents, potentially leveraging Hermes or similar frameworks, were responsible for stealing an estimated 600,000 credit card details and infecting over 100 websites with skimming scripts. This prior evidence paints a grim picture of the potential destructive power of AI-powered malware.

In the context of Carbonato, the Hermes Agent acts as the central nervous system for the compromised host. It receives task commands directly from the operators via Telegram. These commands can encompass a wide range of malicious actions, including the exfiltration of sensitive data such as AI API keys, SSH credentials, and access tokens. The AI agent is also tasked with executing arbitrary commands on the victim system and relaying the results back to the attackers.

ThreatDown researchers describe this as an "interactive command loop," where the AI model plays a crucial role in interpreting tasks, generating terminal commands, analyzing output, and dynamically deciding on subsequent actions. As ThreatDown researchers noted, "The ‘model’ ‘interprets’ ‘the’ ‘task,’ ‘writes’ ‘terminal’ ‘commands,’ ‘reads’ ‘the’ ‘output,’ and ‘decides’ ‘what’ ‘to’ ‘do’ ‘next.’" This iterative process allows for dynamic and adaptive attacks, making it more challenging for traditional security measures to detect and thwart. The agent then executes these commands on the victim machine and returns its findings to the Telegram chat, which also serves as the central hub for deployment notifications.

Worm-Like Propagation and Evolving Tactics

Carbonato’s worm-like characteristics are a significant factor in its potential for rapid proliferation. The malware is designed to actively seek out and infect other vulnerable Docker daemons. This is achieved through scripts that continuously scan the networks connected to the compromised host, performing network sweeps every five minutes. This aggressive scanning ensures that any newly discovered unsecured Docker hosts are quickly identified and targeted.

Upon successfully compromising a new host, the process repeats: the malware pulls the implant from the registry, launches a privileged container, and initiates the persistence and scanning loop. This self-propagating nature means that a single initial compromise can lead to a cascading effect, rapidly expanding the botnet’s reach. The efficiency of this propagation mechanism, combined with the AI’s adaptive capabilities, presents a formidable challenge for defenders.

Attribution and Geographical Indicators

While ThreatDown has been unable to definitively attribute Carbonato to any specific, known threat actor groups, their analysis has yielded some intriguing geographical indicators. Based on various pieces of evidence uncovered during their investigation, researchers suggest that Costa Rica may be the geographical location of the Carbonato operators. Further investigation and intelligence gathering will be necessary to confirm this hypothesis and potentially link the malware to broader cybercriminal networks. The presence of the "CARBONATO_API_KEY" setting and unexpected Telegram traffic directed towards AS262145 (an autonomous system number often associated with a significant internet service provider in Latin America) are some of the clues that point towards this region.

New Carbonato malware uses AI agents to hijack exposed Docker hosts

The Broader Implications of AI-Powered Botnets

The emergence of Carbonato signifies a concerning evolution in the cyber threat landscape. The integration of AI agents like Hermes into botnet operations elevates the sophistication and adaptability of malware. This allows attackers to move beyond static, pre-programmed attack routines and engage in dynamic, real-time exploitation and data exfiltration. The ability of AI agents to interpret commands, execute them, and adapt their strategies based on the environment they are operating in presents a significant challenge for current security defenses.

The implications of such AI-powered botnets are far-reaching:

  • Increased Automation and Scale: AI agents can automate complex tasks that previously required human intervention, enabling attackers to operate at a much larger scale and with greater efficiency.
  • Enhanced Evasiveness: The adaptive nature of AI agents can help malware evade traditional signature-based detection methods. They can modify their behavior in response to security measures, making them harder to identify and block.
  • Sophisticated Data Exfiltration: AI can be used to identify and extract high-value data more effectively, prioritizing sensitive information and optimizing exfiltration channels.
  • New Attack Vectors: The use of AI in conjunction with tools like Docker allows for the exploitation of complex infrastructure in novel ways, creating new attack vectors that security teams may not have anticipated.
  • Democratization of Advanced Attacks: As AI tools become more accessible, the barrier to entry for sophisticated cyberattacks may be lowered, potentially empowering a wider range of malicious actors.

Mitigation and Prevention Strategies

The primary recommendation for organizations to defend against Carbonato and similar threats is to rigorously secure their Docker environments. ThreatDown researchers strongly advise the following:

  • Isolate Docker Daemon APIs: Ensure that Docker daemon APIs are not exposed directly to the public internet. Access should be restricted to trusted internal networks and secured with strong authentication mechanisms.
  • Implement Strong Authentication: Whenever Docker registries or daemons are accessible over a network, robust authentication protocols must be enforced. This prevents unauthenticated access that Carbonato exploits.
  • Regular Security Audits and Patching: Conduct regular security audits of Docker configurations and ensure that all Docker components and host systems are kept up-to-date with the latest security patches.
  • Network Segmentation: Implement network segmentation to limit the lateral movement of malware within an organization’s infrastructure. If one Docker host is compromised, segmentation can prevent the infection from spreading to other critical systems.
  • Monitor for Anomalous Activity: Establish comprehensive monitoring for unusual network traffic, particularly outbound connections to Telegram and unexpected SSH tunnels.

Indicators of Compromise (IoCs)

Organizations should remain vigilant and monitor their environments for the following key indicators of a Carbonato attack:

  • Presence of a "GH0ST" persona file: Specifically, the overwriting of the default "SOUL.md" file with instructions related to the GH0ST agent.
  • "CARBONATO_API_KEY" setting: The presence of this specific API key configuration within the compromised environment.
  • Unexpected Telegram traffic: Significant or unusual communication patterns directed towards Telegram servers.
  • Reverse SSH tunnels toward AS262145: Unexplained reverse SSH connections originating from internal systems and terminating in the network range associated with AS262145.

The emergence of Carbonato serves as a stark reminder of the ever-evolving nature of cyber threats and the increasing sophistication of attackers. The integration of AI agents into malware campaigns poses a significant challenge, requiring organizations to adopt more proactive and adaptive security strategies. By understanding the tactics, techniques, and procedures employed by Carbonato, and by implementing robust security best practices, organizations can better defend themselves against this growing threat. The ongoing arms race between attackers and defenders necessitates continuous innovation in security technologies and a commitment to staying ahead of emerging attack methodologies.

Related Posts

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

The U.S. Treasury Department has imposed sanctions on eight key members of the notorious Venezuelan criminal organization, Tren de Aragua (TdA), for their central roles in orchestrating a sophisticated and…

GitLab Issues Urgent Patch for Critical AI Gateway Vulnerability Enabling Arbitrary Code Execution

GitLab has issued a critical security advisory, urging its customers to immediately apply patches for a severe vulnerability within its AI Gateway service. This flaw, identified as CVE-2026-90970, poses a…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience