Docker Daemons & AI Ecosystems — Carbonato Malware Threat with Autonomous Propagation Capabilities (N/A)
Publication date: September 24, 2026
Category: AI attacks (LLM/LocalAI) (realtime trigger)
Introduction
Threat intelligence researchers at ThreatDown have uncovered a novel botnet and malware campaign dubbed Carbonato, which actively targets servers and Docker daemons exposed to the internet without proper authentication controls. This threat stands out by combining worm-like autonomous propagation capabilities with advanced Artificial Intelligence (AI) agents powered by the Hermes Agent framework. The incident demonstrates how malicious actors are successfully automating complex operations using language models integrated directly into compromised infrastructure.
What is Carbonato and the Use of AI Agents? (General Analysis)
Carbonato is an automated infection vector designed to exploit misconfigured container platforms. Specifically, the malware scans for Docker instances exposing their standard management API on port 2375 without requiring credentials or TLS encryption. The severity of this misconfiguration stems from the fact that interacting with the Docker daemon grants root-level administrative privileges over the underlying host.
To classify this risk in the absence of a formally assigned CVE identifier, severity is estimated as Critical under the CVSS v3.1 standard with an estimated score of 9.8/10 (Estimated Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), owing to unauthenticated remote code execution and full system takeover. The underlying weakness classification corresponds to CWE-306: Missing Authentication for Critical Function Functionality.
What is truly innovative and alarming in Carbonato’s architecture is the integration of the Hermes Agent AI framework. Rather than requiring constant human intervention for each stage of the attack, the malware deploys an autonomous agent codenamed “GH0ST” (overwriting the default SOUL.md persona file). This agent interprets instructions received via Telegram, dynamically generates terminal commands, evaluates command outputs, and autonomously decides subsequent operational steps on the victim’s infrastructure.
How Does It Work? (Technical Analysis)
The compromise and operational lifecycle of Carbonato comprises highly automated phases ranging from initial access to persistence and interactive AI-driven control:
- Initial infection flow and access: The malware scans networks looking for Docker daemons exposed on TCP port
2375. Upon identifying an accessible target, it connects to the API and instructs the daemon to download and launch a privileged container from an unauthenticated registry hosting over 60 malicious repositories. This privileged container breaks kernel isolation, granting full access to the host. - Persistence and evasion: Once inside the host, automated scripts establish multiple persistence mechanisms to ensure the implant survives reboots or surface-level cleanups. These mechanisms include cron jobs, systemd timers,
rc.localhooks, and OpenRC initialization scripts. Additionally, a reverse SSH tunnel is established, an SSH server is installed with the operators’ public key, and deployment notifications are sent through Telegram. - Interactive AI command loop: The operational core leverages the Hermes Agent (“GH0ST” profile) to maintain smooth communication with attackers via Telegram. The agent harvests AI API keys, access tokens, and SSH credentials. Its defining feature is its interactive loop: the model interprets operational directives, executes commands in the infected system’s terminal, reads results, and decides next tactical moves autonomously.
- Worm-like propagation: The malware includes built-in network scanning routines that examine subnets attached to the compromised host every five minutes. Upon detecting newly vulnerable Docker daemons, it automates the exact same attack vector to replicate the implant and expand the botnet.
Affected Systems / Environments
The threat directly impacts a variety of misconfigured technology environments:
- Virtual Private Servers (VPS) and cloud infrastructure nodes exposing TCP port
2375(unauthenticated Docker API). - Private or public container registries hosting malicious images linked to the botnet ecosystem.
- Organizations lacking proper network segmentation or TLS certificate-based access controls for the Docker daemon API.
Mitigation and Detection
Remediation
To neutralize and prevent Carbonato infections, system administrators must enforce the following hardening measures:
- Disable TCP API exposure: Never expose the Docker daemon over unauthenticated TCP ports (
2375or2376without mTLS). If remote administration is required, use exclusively restricted Unix sockets or configure mutual authentication via robust TLS certificates. - Container auditing: Regularly audit for unauthorized privileged containers or those mounting the host root filesystem (
/). - Registry control: Restrict the use of external container registries and validate the integrity of deployed images.
Detection
Defensive teams (Blue Teams) should actively hunt for the following Indicators of Compromise (IoCs):
- Presence of the modified
SOUL.mdpersona file or references to theGH0STagent associated with Hermes Agent. - Configuration of specific environment variables such as
CARBONATO_API_KEY. - Anomalous or unexpected network traffic directed toward the Telegram messaging platform from backend infrastructure servers.
- Reverse SSH tunnel connections directed toward autonomous system
AS262145.
Threat Intelligence Warning: Automating attacks through AI agents like Hermes Agent drastically reduces attacker dwell time and adaptation cycles, turning minor infrastructure exposures into critical breaches within minutes.
Wrapping Up
The emergence of Carbonato malware marks a turning point in the evolution of container-oriented botnets, combining classic Docker misconfiguration vulnerabilities with autonomous decision-making capabilities provided by Artificial Intelligence agents. The ability to evaluate environments, write commands in real time, and exfiltrate data without direct human intervention underscores the urgent need to adopt least-privilege security postures across modern cloud architectures.
References
- BleepingComputer. (2026, September 24). New Carbonato malware uses AI agents to hijack exposed Docker hosts. BleepingComputer. https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/