LmCast :: Stay tuned in

New Carbonato malware uses AI agents to hijack exposed Docker hosts

Recorded: Sept. 24, 2026, 8:10 p.m.

Original Summarized

New Carbonato malware uses AI agents to hijack exposed Docker hosts

News

Featured
Latest

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

New Windows Defender zero-day blocks Microsoft antivirus updates

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Check Point warns of Management Server zero-day exploited in attacks

Drop monthly subscriptions with a $79.99 lifetime PDF editor for Mac

Exposed GitLab project email addresses let attackers push code

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

Hackers now exploit critical Roundcube flaw in code injection attacks

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityNew Carbonato malware uses AI agents to hijack exposed Docker hosts

New Carbonato malware uses AI agents to hijack exposed Docker hosts

By Bill Toulas

September 24, 2026
04:10 PM
0

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data.
ThreatDown researchers at cybersecurity company Malwarebytes retrieved operational evidence spanning October 2024 to August 2026. The archive also included details about the botnet and a separate campaign that distributed counterfeit cryptocurrency wallet apps.
According to Malwarebytes, Carbonato spreads across Docker hosts with an API exposed on port 2375 without authentication.
The malware connects to that API and instructs the daemon to launch a privileged container, giving it access to the host.
It then opens a reverse SSH tunnel, installs an SSH server with the operators’ key, and reports the new deployment through Telegram. At the same time, scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.
One notable aspect of the attack is that the AI agent framework Hermes Agent is installed on the hosts, using an agent named “GH0ST,” with instructions that overwrite the default ‘SOUL.md’ persona file.

The GH0ST agent instructionsSource: ThreatDown
Hermes has been extensively abused in malicious cyber-operations recently. Recently, cybersecurity company Gambit documented a large-scale card-skimming operation that stole 600.000 credit card details.
In the case of Carbonato, Hermes handles task commands received through Telegram, including collecting AI API keys, SSH credentials, access tokens, and other data, running commands, and sending back the results.
The researchers describe this as an operator-driven process involving an “interactive command loop” exchange.
“The​ ​model​ ​interprets​ ​the​ ​task,​ ​writes​ ​terminal​ ​commands,​ ​reads​ ​the​ ​output,​ ​and​ ​decides​​ what ​​to​​ do ​​next,” ThreatDown researchers note.
“​The​​ agent ​​runs ​​those​​ commands ​​on ​​the ​​victim​​ and​ ​returns​ ​its​ ​report​ ​to​ ​the​ ​Telegram​ ​chat​ ​that​ ​also​ ​receives​ ​deployment​ ​reports.​​”
The malware’s worm-like capability allow it to spread to other exposed Docker daemons and is handled by scripts that scan networks attached to the host every five minutes.
Each new compromise pulls the implant from the registry, launches the same privileged container, and enters the persistence and scanning loop.
ThreatDown could not attribute Carbonato to any known threat clusters, but based on various evidence, points to Costa Rica as a possible location of the operator.
To prevent infection, the researchers recommend keeping Docker daemon APIs off the network and requiring authentication on registries.
Signs of Carbonato attacks include a GH0ST persona file, the CARBONATO_API_KEY setting, unexpected Telegram traffic, and reverse SSH tunnels toward AS262145.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
New ClosedQuorum Windows malware uses AI for attack decisionsNew RatHat Android malware uses AI to automate device controlSpain's data agency gets first report of AI-powered data breachAI-powered attack exploited PaperCut flaws to hack 395 organizationsHackers build AI frameworks for widescale credential theft

AI
AI Agent
Artificial Intelligence
Botnet
Carbonato
Docker
Hermes
Malware

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Microsoft reminds admins to migrate Entra ID users to passkeys

New Windows Defender zero-day blocks Microsoft antivirus updates

Sponsor Posts

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

AI is a data-breach time bomb: Read the new report

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready?

Overdue a password health-check? Audit your Active Directory for free

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A new botnet malware named Carbonato utilizes artificial intelligence agents to compromise and hijack exposed Docker hosts. This malware operates with worm-like capabilities, originating from an unauthenticated Docker registry that contained approximately sixty repositories and four point three gigabytes of image data. Researchers from ThreatDown, working with Malwarebytes, retrieved operational evidence spanning from October 2024 to August 2026 detailing both the botnet operations and a separate campaign involving counterfeit cryptocurrency wallet applications.

Carbonato spreads across Docker hosts by exploiting an exposed Application Programming Interface (API) on port 2375 that lacks authentication. Upon connection, the malware instructs the Docker daemon to launch a privileged container, thereby gaining access to the underlying host system. To establish persistence, the malware sets up a reverse SSH tunnel, installs an SSH server using the operators’ keys, and configures various persistence mechanisms, including cron jobs, systemd timers, rc.local, and OpenRC hooks.

A critical feature of this attack is the installation of the Hermes Agent AI framework on the compromised hosts, utilizing an agent designated as “GH0ST.” This agent is responsible for executing task commands received via Telegram, which involves an interactive command loop where the model interprets the task, writes terminal commands, reads the output, and determines subsequent actions. The Hermes framework is used by Carbonato to collect sensitive data, including AI API keys, SSH credentials, and access tokens, before reporting the results back through the Telegram chat.

The malware's worm-like nature allows it to propagate to other exposed Docker daemons by scanning the network attached to the host every five minutes. Each successful compromise involves pulling the implant from the registry, launching the same privileged container, and initiating the persistence and scanning loop. Although the researchers could not attribute Carbonato to any known threat clusters, the evidence suggests a possible operational location in Costa Rica. To mitigate the risk of infection, the researchers recommended that organizations ensure Docker daemon APIs are kept off the network and require authentication for access to registries. Indicators of a Carbonato attack include the presence of a GH0ST persona file, the setting of the CARBONATO_API_KEY, unexpected traffic to Telegram, and reverse SSH tunnels directed toward the IP address AS262145.