Carbonato Botnet Exploits Exposed Docker API

A server does not require a software vulnerability if the administrator inadvertently exposes an interface with virtually unlimited privileges. The ThreatDown team detailed the Carbonato botnet, which actively scans for unauthenticated Docker daemons on TCP port 2375. Consequently, it hijacks the host and transforms it into an AI-managed node. Specialists breached the Carbonato infrastructure in August 2026 via an exposed Docker Registry. This repository had remained accessible from the internet since at least May.
Within a single day of passive collection, investigators successfully retrieved 59 repositories and 234 image tags. They also found 605 verified data objects and 4.3 gigabytes of information. This archive spanned from October 2024 to August 2026. Ultimately, it uncovered two interconnected operations. The first was a formidable botnet. The second was a trojanized cryptocurrency wallet factory.
Gaining Root Access Through the Docker API
For its initial intrusion, Carbonato does not exploit a specific Docker vulnerability. Instead, the botnet leverages the open API to launch a highly privileged container. It meticulously mounts the host’s root file system, process spaces, and network interfaces. Then, it executes commands directly upon the host machine. Furthermore, official documentation explicitly warns that securing remote access to the Docker daemon is essential. An unprotected interface can effortlessly grant an outsider complete root privileges.
Upon establishing persistence, the script initiates a reverse SSH tunnel to a relay stationed in Costa Rica. It injects the attackers’ cryptographic key and transmits comprehensive details regarding the newly conquered node via Telegram. The rogue container cleverly masquerades as the “systemd-resolved” service. Meanwhile, its process arguments convincingly mimic a standard “kworker” system thread. To survive unexpected system reboots, Carbonato manipulates cron jobs and systemd timers. It also alters rc.local scripts and OpenRC configurations. Subsequently, it locks the newly generated files to render them completely immutable.
Deploying AI Agents for Post-Exploitation
The most extraordinary phase of this attack chain commences immediately following the initial hijack. Attackers deploy an unmodified, open-source Hermes Agent from Nous Research onto the server. However, they completely replace its behavioral instruction file. Within a concise 39-line prompt, the agent adopts the designation “GH0ST”. It receives strict orders to maintain persistent access and execute the operator’s precise commands. Astonishingly, the ultimate prize is declared to be AI service API keys. Attackers value these far above traditional SSH credentials, authentication tokens, and databases.
Commands arrive stealthily via Telegram. This prompts Hermes to transmit the task alongside its newly assigned malicious persona directly to a language model gateway. The operators control this gateway entirely. The sophisticated model formulates precise terminal commands and carefully reads the output. Next, it logically selects the subsequent step. Meanwhile, the agent executes these actions on the infected server. It diligently returns a comprehensive report to the designated chat. In this unique scenario, artificial intelligence assists exclusively during the post-exploitation phase.
Automated Propagation and Defense Strategies
The relentless propagation of Carbonato remains entirely automated through conventional scripting methodologies. Every five minutes, the infected node methodically iterates through connected networks and Docker bridges. It aggressively scans subnets searching for port 2375. Then, it meticulously evaluates any discovered services. Finally, it ruthlessly repeats the entire infection chain upon vulnerable new hosts. Similar self-propagating logic targeting cloud infrastructure has previously emerged in various other malicious worms.
Digital footprints within the infrastructure suggest a potential connection between the operators and Costa Rica. However, ThreatDown does not consider this isolated indicator sufficient for a definitive, ironclad attribution. Multiple factors point toward this nation simultaneously. These include a specific time zone embedded within partial configurations and a Telegram handle matching the local country code. Furthermore, the central network where the reverse SSH tunnels ultimately converge points to this location.
To ensure robust defense, ThreatDown strongly advises against exposing the Docker API to the public internet without proper authentication. Administrators must secure open registries and thoroughly inspect servers for the characteristic digital footprints of Carbonato. Security teams generally advise against blindly blocking the Hermes Agent itself, as the foundational project remains entirely legitimate. Finally, it is absolutely essential to inventory and meticulously rotate any AI service API keys if they were stored on the compromised nodes.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.