< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 6 sources · 3 days · First seen · Last updated

Carbonato malware and AI-driven botnet

Overview

Security researchers have identified a new malware campaign and botnet named Carbonato that targets unprotected Docker hosts. The malware specifically scans for Docker Daemons with their API exposed on port 2375 without authentication. Once a connection is established, it launches a privileged container to gain full host access and establishes persistence through methods such as cron jobs and systemd timers.

A defining feature of this campaign is the use of the open-source Hermes Agent framework, specifically an instance renamed ‘GH0ST’. This autonomous AI agent acts as a command-and-control engine, using an ‘interactive command loop’ via Telegram to interpret tasks and execute terminal commands.

Unlike traditional botnets, Carbonato uses the AI agent to reason through its environment and adapt to specific host configurations. The attackers focus on stealing sensitive AI service API keys from providers including OpenAI, Anthropic, and Google, which are reportedly used to fund the operators’ own LLM gateway.

Entities

Carbonato · ThreatDown · Hermes Agent · Malwarebytes · Nous Research

Timeline

  1. [TECHNOLOGY] 3 sources
    CARBONATO botnet uses autonomous AI agents for command-and-control

    ThreatDown researchers discovered CARBONATO, a Docker-based botnet that uses an autonomous AI agent for command-and-control, automating reconnaissance and prioritizing the theft of AI API keys.

  2. [TECHNOLOGY] 3 sources
    Carbonato malware targets unprotected Docker hosts with AI agents

    The Carbonato malware targets unprotected Docker hosts to install GH0ST, an AI agent that autonomously executes commands and steals credentials via Telegram.

Sources

blogspan.net · cybernoz.com · flagthis.com · forkast.news · moncloa.com · tomshw.it