New Carbonato Malware Uses AI Agents to Hijack Exposed Docker Hosts

A new strain of malware, dubbed Carbonato, has emerged as a significant threat to enterprises utilizing Docker containers. This botnet malware specifically targets insecure Docker hosts to deploy the Hermes Agent AI framework, enabling attackers to gain unauthorized control over affected systems. The implications of this attack vector are profound, particularly for organizations relying on containerization for their operations.

Technical Analysis

Carbonato operates by exploiting Docker daemons that are exposed on port 2375 without authentication. This vulnerability allows the malware to connect to the Docker API and instruct the daemon to launch a privileged container, effectively granting the attacker access to the host system. Once inside, Carbonato establishes a reverse SSH tunnel, installs an SSH server using the operator's key, and reports its activities via Telegram.

The malware also implements persistence mechanisms by creating cron jobs, systemd timers, rc.local entries, and OpenRC hooks. This ensures that even if the initial infection is removed, the malware can re-establish itself on the host.

Affected Systems

Carbonato primarily targets systems running Docker daemons that are improperly configured. Specifically, any Docker host that exposes the API on port 2375 without authentication is at risk. This includes both cloud-based and on-premises deployments, making it a widespread concern for organizations utilizing container orchestration.

Attack Method / Threat Activity

Upon successfully exploiting a vulnerable Docker host, Carbonato installs the Hermes Agent AI framework, utilizing an agent known as “GH0ST.” This agent is programmed to overwrite the default ‘SOUL.md’ persona file, facilitating the execution of commands received through Telegram. The operational capabilities of Hermes include:

  • Collecting sensitive information such as AI API keys, SSH credentials, and access tokens.
  • Executing commands on the compromised host and returning results to the operator.
  • Maintaining an interactive command loop for real-time control.

This sophisticated command-and-control mechanism underscores the threat posed by Carbonato, particularly as it leverages AI to enhance its operational efficiency.

Detection Opportunities

Organizations can implement several detection strategies to identify Carbonato-related activities:

📬 Stay ahead of the threat

Get the latest SOC guides, threat intel, and detection engineering — straight to your inbox.

  • Monitor network traffic for unusual connections to port 2375, especially from untrusted sources.
  • Utilize SIEM solutions to analyze logs for unauthorized API calls or the creation of privileged containers.
  • Implement threat hunting practices to identify signs of reverse SSH tunnels or unexpected cron jobs.

Regular audits of Docker configurations and access controls can also help in detecting potential vulnerabilities before they are exploited.

Mitigation Recommendations

To protect against Carbonato and similar threats, organizations should consider the following mitigation strategies:

  • Disable unauthenticated access to the Docker API by configuring it to listen only on localhost or implementing strong authentication mechanisms.
  • Regularly update Docker and its components to the latest versions to patch known vulnerabilities.
  • Employ network segmentation to limit exposure of Docker hosts to the internet.
  • Conduct security awareness training for teams managing containerized applications to recognize and respond to potential threats.

Business Impact

The emergence of Carbonato poses significant risks to businesses, particularly those that rely on Docker for their application deployments. A successful attack could lead to:

  • Data breaches involving sensitive information.
  • Operational disruptions as systems are compromised or taken offline.
  • Financial losses due to recovery efforts and potential regulatory fines.

Understanding the threat landscape and implementing robust security measures is essential for minimizing the impact of such malware.

Final Summary

Carbonato represents a new frontier in malware targeting Docker environments, utilizing AI-driven tactics to enhance its effectiveness. By exploiting misconfigured Docker daemons, it can gain control over hosts and execute a range of malicious activities. Organizations must prioritize securing their containerized applications, employing both proactive detection and robust mitigation strategies to safeguard against this evolving threat.