Carbonato is a new botnet malware that targets unsecured Docker daemons to deploy the Hermes Agent AI framework and gain control of hosts. It uses worm-like spreading, persistence mechanisms, and Telegram-based operator commands, with signs of compromise including the GH0ST persona file and CARBONATO_API_KEY. #Carbonato #HermesAgent #GH0ST #Docker
Keypoints
- Carbonato targets Docker daemons exposed on port 2375 without authentication.
- It launches a privileged container to access and control the host.
- The malware installs Hermes Agent with a GH0ST persona file for operator-driven tasks.
- It uses reverse SSH tunnels, Telegram, and multiple persistence methods to stay active.
- Carbonato can scan and spread to other exposed Docker hosts every five minutes.