New Carbonato malware uses AI agents to hijack exposed Docker hosts
Carbonato is a botnet malware targeting insecure Docker hosts with exposed, unauthenticated Docker daemon APIs on port 2375. It installs the Hermes Agent AI framework, specifically the GH0ST agent, to execute operator-driven commands via Telegram, enabling remote control and data theft. The malware spreads worm-like by scanning networks for other vulnerable Docker daemons and establishing persistence through multiple system mechanisms. Infection signs include the GH0ST persona file, the CARBONATO_API_KEY setting, reverse SSH tunnels, and unusual Telegram traffic. Researchers suggest the operator may be located in Costa Rica. Mitigation involves securing Docker APIs by disabling network exposure and enforcing authentication on registries.
AI Analysis
Technical Summary
Carbonato malware targets Docker hosts with exposed, unauthenticated Docker daemon APIs (port 2375). It exploits this to launch privileged containers, gaining host access, then installs the Hermes Agent AI framework with the GH0ST agent. This agent operates interactively via Telegram, executing commands, collecting credentials, and exfiltrating data. The malware establishes persistence using cron jobs, systemd timers, rc.local, and OpenRC hooks. It has worm-like capabilities, scanning attached networks every five minutes to propagate to other vulnerable Docker hosts. Operational evidence spans from October 2024 to August 2026. The malware's operator-driven AI agent interprets tasks, runs commands on victims, and reports results back through Telegram. Indicators include the GH0ST persona file and reverse SSH tunnels to AS262145. Researchers recommend disabling exposed Docker APIs and enforcing authentication to prevent infection.
Potential Impact
Successful exploitation allows attackers to gain privileged access to Docker hosts, install a persistent AI-driven agent capable of executing arbitrary commands, stealing credentials and tokens, and maintaining remote control via reverse SSH tunnels. The worm-like propagation enables rapid spread across networks with exposed Docker daemons, potentially compromising multiple hosts. The AI agent's interactive command loop facilitates dynamic attacker control and data exfiltration, increasing operational flexibility and stealth.
Mitigation Recommendations
To prevent Carbonato infection, ensure Docker daemon APIs are not exposed on the network and require authentication on Docker registries. These measures effectively block the primary infection vector. Monitor for indicators such as the GH0ST persona file, the CARBONATO_API_KEY environment variable, unexpected Telegram traffic, and reverse SSH tunnels. No official patch is indicated; securing Docker API exposure is the primary defense.
New Carbonato malware uses AI agents to hijack exposed Docker hosts
Description
Carbonato is a botnet malware targeting insecure Docker hosts with exposed, unauthenticated Docker daemon APIs on port 2375. It installs the Hermes Agent AI framework, specifically the GH0ST agent, to execute operator-driven commands via Telegram, enabling remote control and data theft. The malware spreads worm-like by scanning networks for other vulnerable Docker daemons and establishing persistence through multiple system mechanisms. Infection signs include the GH0ST persona file, the CARBONATO_API_KEY setting, reverse SSH tunnels, and unusual Telegram traffic. Researchers suggest the operator may be located in Costa Rica. Mitigation involves securing Docker APIs by disabling network exposure and enforcing authentication on registries.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Carbonato malware targets Docker hosts with exposed, unauthenticated Docker daemon APIs (port 2375). It exploits this to launch privileged containers, gaining host access, then installs the Hermes Agent AI framework with the GH0ST agent. This agent operates interactively via Telegram, executing commands, collecting credentials, and exfiltrating data. The malware establishes persistence using cron jobs, systemd timers, rc.local, and OpenRC hooks. It has worm-like capabilities, scanning attached networks every five minutes to propagate to other vulnerable Docker hosts. Operational evidence spans from October 2024 to August 2026. The malware's operator-driven AI agent interprets tasks, runs commands on victims, and reports results back through Telegram. Indicators include the GH0ST persona file and reverse SSH tunnels to AS262145. Researchers recommend disabling exposed Docker APIs and enforcing authentication to prevent infection.
Potential Impact
Successful exploitation allows attackers to gain privileged access to Docker hosts, install a persistent AI-driven agent capable of executing arbitrary commands, stealing credentials and tokens, and maintaining remote control via reverse SSH tunnels. The worm-like propagation enables rapid spread across networks with exposed Docker daemons, potentially compromising multiple hosts. The AI agent's interactive command loop facilitates dynamic attacker control and data exfiltration, increasing operational flexibility and stealth.
Defensive Guidance
To prevent Carbonato infection, ensure Docker daemon APIs are not exposed on the network and require authentication on Docker registries. These measures effectively block the primary infection vector. Monitor for indicators such as the GH0ST persona file, the CARBONATO_API_KEY environment variable, unexpected Telegram traffic, and reverse SSH tunnels. No official patch is indicated; securing Docker API exposure is the primary defense.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6ab59009f7a7c54106d832fe
Added to database: 09/24/2026, 21:03:05 UTC
Last enriched: 09/24/2026, 21:03:15 UTC
Last updated: 09/25/2026, 04:03:13 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.