Carbonato Botnet Deploys Telegram-Controlled AI Agent on Exposed Docker Hosts

Cloud security operations monitoring exposed Docker hosts and AI-agent malware activity

ThreatDown researchers have documented a botnet called Carbonato that targets Docker daemons exposed without authentication and deploys an open-source AI agent framework for operator-controlled activity. The research was first published on September 22, with additional technical reporting appearing on September 28.

Exposed Docker APIs provide the entry point

The operation searches for Docker services reachable on port 2375 without authentication. After finding one, the malware launches a privileged container, mounts the host filesystem and uses the container to execute commands on the underlying host. It then establishes persistence and scans nearby networks for more exposed daemons.

ThreatDown traced the infrastructure through an unauthenticated registry that exposed repositories, image tags and configuration data. The researchers said the same environment supported a separate operation involving trojanized cryptocurrency wallet applications.

Hermes Agent becomes the operator interface

Carbonato installs Hermes Agent without modifying the framework itself, then replaces its persona file with instructions that prioritize persistence, command execution and credential collection. Operators submit tasks through Telegram, while the agent connects to a model gateway and converts those instructions into terminal activity.

The research highlights a practical cloud-security failure rather than a novel Docker vulnerability: administrative APIs should not be directly exposed without authentication. Organizations can reduce risk by restricting daemon access, authenticating registries, reviewing privileged containers and monitoring for unexpected persistence. The incident adds another example to SectechMedia coverage of Cyber-Physical Security as AI tooling moves into real attack chains.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *