Back
Carbonato malware hijacks exposed Docker hosts with AI agents
SiTech AI Team2 წთ. საკითხავი

Carbonato malware hijacks exposed Docker hosts with AI agents

A new botnet called Carbonato targets Docker daemons whose API is exposed on port 2375 without authentication, launches privileged containers and installs the Hermes Agent AI framework, steered through Telegram, to control the host.

A new botnet called Carbonato targets hosts running Docker daemons whose API is exposed without authentication, and installs the Hermes Agent AI framework to take control of them. BleepingComputer reported the case on 24 September 2026, citing ThreatDown research at Malwarebytes.

Carbonato behaves like a worm and spreads from one vulnerable host to the next. Investigators found the operation through an unauthenticated Docker registry holding almost 60 repositories and 4.3 GB of image data, with evidence spanning October 2024 to August 2026 and details of a separate campaign that spread counterfeit crypto wallet apps.

From port 2375 to the host

According to the researchers, Carbonato spreads across Docker hosts whose API is reachable on port 2375 without authentication. The malware connects to that API and tells the daemon to launch a privileged container, which gives it access to the underlying host.

It then opens a reverse SSH tunnel, installs an SSH server with the operators' key and reports the new deployment through Telegram. Scripts also create cron jobs, systemd timers, rc.local entries and OpenRC hooks so the intrusion survives reboots.

An AI agent driven over Telegram

The Hermes Agent framework is installed on the compromised host with an agent named "GH0ST", whose instructions overwrite the default SOUL.md persona file. Hermes handles tasks received through Telegram: collecting AI API keys, SSH credentials and access tokens, running commands and returning the results.

The GH0ST agent instructions, source: ThreatDown

ThreatDown describes an operator-driven "interactive command loop": the model interprets the task, writes terminal commands, reads the output and decides what to do next, then returns its report to the same Telegram chat that receives the deployment notices.

Scanning, attribution and protection

The worm-like capability relies on scripts that scan networks attached to the host every five minutes for more exposed Docker daemons. Each new compromise pulls the implant from the registry, starts the same privileged container and re-enters the persistence and scanning loop. ThreatDown could not tie Carbonato to a known threat cluster, but several pieces of evidence point to Costa Rica as the operator's possible location.

They recommend keeping Docker daemon APIs off the network and requiring authentication on registries. Signs of infection include a GH0ST persona file, the CARBONATO_API_KEY setting, unexpected Telegram traffic and reverse SSH tunnels toward AS262145.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.