Description

Cybersecurity researchers have disclosed Carbonato, a botnet that targets Docker daemons exposed without authentication on TCP port 2375. It compromises vulnerable hosts by launching privileged containers, executing commands on the underlying system, establishing persistence, and scanning neighboring networks every five minutes to spread to additional Docker hosts. The malware also creates a reverse SSH tunnel to infrastructure in Costa Rica and reports compromised systems through Telegram. Carbonato deploys the open-source Hermes Agent framework and replaces its SOUL.md persona with instructions that turn the agent into a Telegram-controlled operator. The AI agent receives commands from attackers through Telegram, sends tasks to an LLM gateway, executes the resulting terminal commands, and returns results to the attackers. Persistence is maintained through cron jobs and watchdog scripts, while the malware attempts to evade detection by masquerading as a system component. The advisory also highlights the broader use of AI agents in cyberattacks, including campaigns involving Hermes, Strix, and Cairn, as well as the CLOSEDQUORUM Windows implant, which uses multiple LLM providers to determine post-compromise actions. Reported activities include credential theft, exploitation, lateral movement, persistence, and payment-card data theft. The Carbonato operation has not been attributed to a known threat group, although infrastructure and language clues reportedly point to Costa Rica.