Docker and Malwarebytes: New Carbonato malware uses AI agents to hijack exposed Docker hosts

Docker and Malwarebytes: New Carbonato malware uses AI agents to hijack exposed Docker hosts

New Carbonato Botnet Exploits Exposed Docker Hosts to Deploy AI-Powered Malware

A recently discovered botnet malware, Carbonato, is targeting insecure Docker daemons to deploy the Hermes Agent AI framework, granting attackers persistent control over compromised systems. Researchers at Malwarebytes’ ThreatDown team uncovered the campaign after analyzing an unauthenticated Docker registry containing nearly 60 repositories and 4.3 GB of image data, with operational evidence dating from October 2024 to August 2026.

Carbonato spreads by scanning for Docker hosts with unauthenticated API access on port 2375, a common misconfiguration. Once a vulnerable host is identified, the malware instructs the Docker daemon to launch a privileged container, enabling full access to the underlying system. It then establishes a reverse SSH tunnel, installs an SSH server with the attackers’ key, and reports new infections via Telegram.

For persistence, Carbonato deploys cron jobs, systemd timers, rc.local, and OpenRC hooks, ensuring it remains active even after reboots. The malware also installs Hermes Agent, an AI framework configured with a custom "GH0ST" persona that overwrites the default SOUL.md file. Hermes operates as an interactive command loop, interpreting tasks from Telegram such as harvesting AI API keys, SSH credentials, and access tokens executing commands on the victim’s system, and returning results to the attackers.

Carbonato’s worm-like propagation allows it to scan connected networks every five minutes, spreading to other exposed Docker hosts. Each new compromise follows the same pattern: pulling the implant from the registry, launching a privileged container, and repeating the persistence and scanning cycle.

While ThreatDown could not attribute Carbonato to a known threat group, evidence suggests the operator may be based in Costa Rica. Indicators of compromise include the GH0ST persona file, CARBONATO_API_KEY environment variable, unexpected Telegram traffic, and reverse SSH tunnels linked to AS262145.

The campaign highlights the growing abuse of AI-driven malware in cyber operations, with Hermes previously linked to a large-scale card-skimming attack that stole 600,000 credit card details.

Source: https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/

Malwarebytes cybersecurity rating report: https://www.rankiteo.com/company/malwarebytes

Docker, Inc cybersecurity rating report: https://www.rankiteo.com/company/docker

"id": "MALDOC1790288742",
"linkid": "malwarebytes, docker",
"type": "Vulnerability",
"date": "10/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Global (targeted via unauthenticated '
                                    'Docker APIs)',
                        'type': 'Organizations with exposed Docker hosts'}],
 'attack_vector': 'Exposed Docker API (Port 2375)',
 'data_breach': {'data_exfiltration': 'Yes (via Telegram)',
                 'number_of_records_exposed': '600,000 (historically linked)',
                 'personally_identifiable_information': 'Yes (credentials, '
                                                        'access tokens)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['AI API keys',
                                              'SSH credentials',
                                              'Access tokens',
                                              'Credit card details '
                                              '(historically)']},
 'date_detected': '2024-10',
 'description': 'A recently discovered botnet malware, Carbonato, is targeting '
                'insecure Docker daemons to deploy the Hermes Agent AI '
                'framework, granting attackers persistent control over '
                'compromised systems. The malware spreads by scanning for '
                'Docker hosts with unauthenticated API access on port 2375, '
                'establishing reverse SSH tunnels, and installing an AI-driven '
                'command loop for harvesting credentials and executing '
                'commands.',
 'impact': {'data_compromised': 'AI API keys, SSH credentials, access tokens, '
                                'credit card details (historically linked)',
            'identity_theft_risk': 'High (due to credential harvesting)',
            'operational_impact': 'Persistent malware infection, unauthorized '
                                  'command execution',
            'payment_information_risk': 'High (historically linked to 600,000 '
                                        'credit card details stolen)',
            'systems_affected': 'Docker hosts with exposed APIs'},
 'initial_access_broker': {'backdoors_established': 'Reverse SSH tunnel, SSH '
                                                    'server with attacker’s '
                                                    'key',
                           'entry_point': 'Exposed Docker API (Port 2375)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Exposed Docker APIs are a significant attack vector; '
                    'AI-driven malware is increasingly used in cyber '
                    'operations; persistent malware can spread via worm-like '
                    'propagation.',
 'motivation': 'Persistent control, credential harvesting, AI-driven command '
               'execution',
 'post_incident_analysis': {'corrective_actions': 'Implement Docker API '
                                                  'authentication, restrict '
                                                  'network access to Docker '
                                                  'hosts, deploy enhanced '
                                                  'monitoring for reverse SSH '
                                                  'tunnels and Telegram '
                                                  'traffic.',
                            'root_causes': 'Unauthenticated Docker daemon '
                                           'access, lack of network '
                                           'segmentation, failure to monitor '
                                           'for unauthorized API usage'},
 'recommendations': 'Secure Docker daemons with authentication, monitor for '
                    'unauthorized API access, detect reverse SSH tunnels and '
                    'Telegram traffic, and audit for indicators of compromise '
                    '(e.g., GH0ST persona, CARBONATO_API_KEY).',
 'references': [{'source': 'Malwarebytes’ ThreatDown team'}],
 'response': {'third_party_assistance': 'Malwarebytes’ ThreatDown team'},
 'title': 'New Carbonato Botnet Exploits Exposed Docker Hosts to Deploy '
          'AI-Powered Malware',
 'type': 'Botnet',
 'vulnerability_exploited': 'Unauthenticated Docker daemon access'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.