Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

A Newly Uncovered Botnet Implants AI Agents onto Compromised Servers to Steal Credentials

Cybersecurity researchers have uncovered a sophisticated botnet that’s using artificial intelligence (AI) agents to carry out attacks on compromised Docker hosts. The botnet, dubbed Carbonato, has been found to implant AI agents onto affected servers, which are then used to send stolen credentials back to the attackers.

The botnet compromises servers running unauthenticated Docker daemons exposed on port 2375, a vulnerability that’s been well-documented since 2013 but still exists in some environments. Once inside, the attackers establish persistence and spread to other reachable Docker hosts. According to researchers from ThreatDown, who discovered the botnet last month, the attackers have been using Telegram to execute commands and steal AI API keys.

One of the most striking aspects of the Carbonato botnet is its use of an open-source AI agent framework called Hermes Agent. This framework allows the attackers to embed a 39-line prompt that directs the agent to “execute tasks received through Telegram, maintain persistence, and collect credentials.” The agent’s primary goal appears to be collecting AI API keys, prioritizing them ahead of other sensitive data.

The botnet malware also includes more conventional scripts that search nearby networks for exposed Docker services, compromise additional hosts, and repeat the infection cycle. ThreatDown researchers did not attribute the campaign to a specific threat actor but noted some clues suggesting the attackers may be based in Costa Rica.

It’s worth noting that port 2375 is an unencrypted REST API endpoint for remote connections to the Docker daemon. While it’s not a novel initial access vector, the botnet attack relies on users actively exposing this port, which Docker advises against doing. In fact, Docker has never received a report about developers encountering issues with this vulnerability.

The discovery of the Carbonato botnet highlights the ongoing threat posed by AI-powered attacks. As more organizations adopt AI and machine learning technologies, they also become potential targets for attackers looking to exploit these vulnerabilities. To mitigate such risks, defenders should not expose the Docker daemon API to the network and require authentication on every registry. Additionally, they can hunt for abuse signatures related to this botnet campaign.

In practical terms, users running Docker environments should review their configurations and ensure that port 2375 is not exposed to the internet. This simple step can go a long way in preventing attacks like Carbonato from succeeding.


Source: Dark Reading — 2026-09-28