Carbonato Botnet Uses AI Agents to Take Over Exposed Docker Servers
Researchers have found a worm-like botnet called Carbonato that hijacks Docker servers left open to the internet and installs an AI agent to steal credentials and run commands on the attackers' behalf.
What happened
Security researchers at ThreatDown have described a new botnet↗ called Carbonato. It spreads like a worm↗, targets servers running Docker, and then installs an AI agent framework that helps the attackers control the compromised machines. The finding is a clear example of criminals adding AI agents to the same automated tools they already use to break into systems.
The researchers found the malware↗ in an unprotected Docker registry, a storage location for container images that had no password. It held nearly 60 repositories and about 4.3 GB of data. According to the reporting, the material also gave a view of the operation's activity stretching from October 2024 to August 2026. Who is behind it is still unclear, although the evidence suggests a possible link to Costa Rica.
How the attack works
Docker is a popular way to run applications in isolated packages called containers. A Docker server can be managed remotely through a network interface known as the Docker API. If that interface is reachable from the internet and does not require authentication↗, anyone who finds it can give the server orders.
Carbonato looks for exactly this situation: Docker hosts with an unauthenticated API exposed on port 2375. Once it finds one, it:
- Tells the Docker daemon to start a privileged container, which has broad access to the underlying machine.
- Opens reverse SSH tunnels, so the attackers can connect back in.
- Installs an SSH server with keys that belong to the attackers.
- Reports each new victim through Telegram.
- Sets up several persistence mechanisms (cron jobs, systemd timers, rc.local and OpenRC hooks) so it survives a restart.
It then behaves like a worm: it scans networks every five minutes looking for more exposed Docker daemons to infect.
Where the AI agent comes in
What makes Carbonato notable is what it installs next. It deploys the Hermes Agent AI framework, configured with an agent persona called "GH0ST". The operators send instructions through Telegram, and the agent carries them out. Tasks described in the report include collecting AI API keys, SSH credentials, access tokens and other data, running commands, and sending the results back.
In practice the agent works in a loop: it interprets a task, writes the terminal commands needed, reads what comes back and decides what to do next. This means an attacker no longer needs to type every command by hand. They can describe a goal and let the agent work through the steps.
Why it matters
None of the entry techniques here are new. Exposed Docker APIs have been abused for years, and the root problem is a simple misconfiguration. What changes is the effort required afterwards. An AI agent can lower the skill and time needed to explore a compromised server and pick out valuable secrets, which is why stolen AI API keys are on the target list alongside traditional credentials. Those keys can be used to run up costs or to power further abuse.
The same pattern applies beyond Docker. Any service that is exposed without authentication is an easy target for automated scanning, and automation is getting more capable.
What you should do
The researchers' advice comes down to a few basic controls:
- Never expose the Docker API to the internet without authentication. Keep it on a private network or a local socket, and if remote access is required, protect it with TLS and client authentication.
- Require authentication on container registries so that internal images and files are not publicly readable.
- Check your own servers. Scan for open port 2375 and review firewall↗ and cloud security↗ group rules.
- Look for warning signs, such as files or settings referring to "GH0ST" or CARBONATO_API_KEY, unexpected Telegram traffic, and reverse SSH tunnels to unfamiliar addresses. The researchers specifically mention traffic toward AS262145.
- Treat secrets as compromised if a host was exposed. Rotate SSH keys, access tokens and AI API keys that were stored on it.
For most people the takeaway is reassuring in one respect: the defence is not new or complicated. Closing an open door, adding a password and keeping management interfaces off the public internet still stops this kind of attack.
Source: BleepingComputer