started · updated
Carbonato malware targets unprotected Docker hosts with AI agents
Researchers from ThreatDown, the security division of Malwarebytes, have identified a malware campaign named Carbonato that targets unprotected Docker hosts. The malware scans the internet for Docker Daemons with their API exposed on port 2375 without authentication.
Once a connection is established, Carbonato launches a privileged container to gain full access to the host. It then establishes a reverse-SSH tunnel and installs its own SSH server to maintain persistence. To ensure it survives system reboots, the malware utilizes multiple methods, including cron jobs, systemd timers, and various hooks.
A notable aspect of this campaign is the deployment of an AI agent framework known as Hermes Agent, specifically an instance called ‘GH0ST’. This agent operates via an ‘interactive command loop’ through Telegram. It can interpret tasks, write terminal commands, read outputs, and autonomously decide on subsequent actions. The agent is used to collect sensitive data, such as AI service API keys, SSH credentials, and access tokens.
Entities
Carbonato · GH0ST · Hermes Agent · Malwarebytes · ThreatDown