New Carbonato malware uses AI agents to hijack exposed Docker hosts

New Carbonato malware uses AI agents to hijack exposed Docker hosts
Carbonato is a new botnet malware that targets unsecured Docker daemons to deploy the Hermes Agent AI framework and gain control of hosts. It uses worm-like spreading, persistence mechanisms, and Telegram-based operator commands, with signs of compromise including the GH0ST persona file and CARBONATO_API_KEY. #Carbonato #HermesAgent #GH0ST #Docker

Keypoints

  • Carbonato targets Docker daemons exposed on port 2375 without authentication.
  • It launches a privileged container to access and control the host.
  • The malware installs Hermes Agent with a GH0ST persona file for operator-driven tasks.
  • It uses reverse SSH tunnels, Telegram, and multiple persistence methods to stay active.
  • Carbonato can scan and spread to other exposed Docker hosts every five minutes.

Read More: https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/