IA et LLM

Carbonato botnet uses AI agents to hijack exposed Docker hosts

The Carbonato botnet targets unauthenticated Docker daemons to deploy Hermes AI agents, enabling automated credential theft and lateral movement via Telegram.

Aperçu de Webhook Inspector

Cet article n’est disponible qu’en anglais.

Security researchers have identified a new malware campaign called Carbonato that exploits exposed Docker daemons to install an artificial intelligence agent framework. Discovered in late September 2026, this botnet leverages the open-source Hermes Agent to automate post-exploitation tasks and maintain persistent access through Telegram commands.

What happened

The Carbonato botnet specifically targets Docker daemons that are exposed to the internet without authentication, typically on port 2375. Once it identifies a vulnerable host, the malware launches a privileged container to execute commands directly on the underlying system. It then establishes persistence by installing an SSH server with the attacker’s key and creating cron jobs and watchdog scripts to ensure the implant survives removal attempts. The operation was initially detected through an unauthenticated Docker registry that had been publicly accessible since May 2026.

After securing access, the malware installs the Hermes Agent framework and overwrites its default persona file, known as SOUL.md. This custom prompt instructs the AI to act as a "senior hacker" named GH0ST, directing it to prioritize collecting credentials and API keys. The agent communicates with operators via Telegram, interpreting their messages and forwarding them to large language model gateways. The resulting terminal commands are executed on the victim's machine, and the output is sent back to the attackers, creating an interactive loop that requires minimal human intervention.

The botnet exhibits worm-like behavior, scanning neighboring networks every five minutes for other exposed Docker daemons to propagate further. Researchers noted that the infrastructure and language clues suggest the operators are based in Costa Rica. While no specific threat group has been attributed to Carbonato yet, its methods align with a broader trend of using AI to automate and accelerate cyberattacks.

Key details

  • Target vector: Unauthenticated Docker daemons exposed on port 2375.
  • Payload: Installs the open-source Hermes Agent framework with a modified SOUL.md persona file.
  • Command and control: Uses Telegram for operator instructions and reporting deployment details.
  • Persistence: Establishes reverse SSH tunnels to a relay in Costa Rica and uses cron jobs for resilience.
  • Propagation: Scans local networks every five minutes to find and infect other vulnerable Docker hosts.
  • AI role: The Hermes Agent interprets natural language commands from attackers and generates executable terminal code.

Background

Docker daemons manage the lifecycle of containers, but when exposed to the public internet without proper authentication, they allow anyone to create and run containers on the host system. Attackers often scan for these open ports to gain root-level access. The Hermes Agent is an open-source framework designed to integrate large language models into autonomous workflows. In legitimate use cases, it might help developers automate testing or data processing. However, in this context, threat actors repurpose it to interpret malicious instructions and generate attack scripts dynamically.

This incident highlights the growing intersection of container security and AI-driven threats. By using an AI agent, attackers can adapt their tactics in real-time, asking the model to find credentials or escalate privileges without needing pre-written scripts for every scenario. This shifts the attack from a static exploit to a dynamic, intelligent process that can react to the specific environment of the compromised host.

Why it matters

For teams running self-hosted software, this campaign underscores the critical importance of securing container management interfaces. Many development environments expose Docker APIs for convenience, but leaving them unauthenticated on public networks creates an easy entry point for automated botnets. The speed at which Carbonato propagates means that a single misconfigured host can compromise an entire network segment within hours. Since the malware uses privileged containers, it bypasses many standard container isolation protections, giving attackers direct control over the host operating system.

The use of AI agents also changes the defensive landscape. Traditional signature-based detection may struggle to identify the varied commands generated by an LLM. Instead of looking for specific malicious strings, security teams must monitor for anomalous behavior, such as unexpected container creation, unusual outbound connections to messaging platforms like Telegram, or high-frequency network scanning from internal hosts. The automation allows attackers to operate at a scale and speed that manual defense strategies often cannot match.

What you can do

  • Restrict Docker API access: Ensure Docker daemons are not exposed to the public internet. Use firewalls to limit access to trusted IP addresses only.
  • Enable authentication: Configure TLS and client certificate authentication for any Docker daemon that must be accessed remotely.
  • Monitor for privileged containers: Set up alerts for the creation of containers running in privileged mode, especially if initiated by unknown users or processes.
  • Audit network traffic: Look for unusual outbound connections to Telegram or unknown SSH relays, which may indicate command-and-control activity.
  • Scan for exposed services: Regularly audit your external-facing assets to identify and secure any unintentionally exposed management interfaces.
  • Implement least privilege: Avoid running containers with root privileges unless absolutely necessary, and use user namespaces to limit potential damage.

Autres actualités

Toutes les actualités