Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 6 sources · 3 days · First seen · Last updated
Carbonato malware and AI-driven botnet
Overview
Security researchers have identified a new malware campaign and botnet named Carbonato that targets unprotected Docker hosts. The malware specifically scans for Docker Daemons with their API exposed on port 2375 without authentication. Once a connection is established, it launches a privileged container to gain full host access and establishes persistence through methods such as cron jobs and systemd timers.
A defining feature of this campaign is the use of the open-source Hermes Agent framework, specifically an instance renamed ‘GH0ST’. This autonomous AI agent acts as a command-and-control engine, using an ‘interactive command loop’ via Telegram to interpret tasks and execute terminal commands.
Unlike traditional botnets, Carbonato uses the AI agent to reason through its environment and adapt to specific host configurations. The attackers focus on stealing sensitive AI service API keys from providers including OpenAI, Anthropic, and Google, which are reportedly used to fund the operators’ own LLM gateway.
Entities
Carbonato · ThreatDown · Hermes Agent · Malwarebytes · Nous Research
Timeline
-
[TECHNOLOGY] 3 sourcesCARBONATO botnet uses autonomous AI agents for command-and-control
ThreatDown researchers discovered CARBONATO, a Docker-based botnet that uses an autonomous AI agent for command-and-control, automating reconnaissance and prioritizing the theft of AI API keys.
-
[TECHNOLOGY] 3 sourcesCarbonato malware targets unprotected Docker hosts with AI agents
The Carbonato malware targets unprotected Docker hosts to install GH0ST, an AI agent that autonomously executes commands and steals credentials via Telegram.
Sources
blogspan.net · cybernoz.com · flagthis.com · forkast.news · moncloa.com · tomshw.it