Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

A newly discovered Docker botnet is implanting AI agents onto compromised hosts in order to send stolen credentials back to attackers, highlighting a growing trend of using artificial intelligence (AI) to amplify cyber threats. The botnet, dubbed Carbonato, exploits exposed Docker daemons on port 2375 to establish persistence and spread to other reachable Docker hosts.

ThreatDown researchers uncovered the botnet last month after identifying an unauthenticated Docker registry that had been publicly exposed since May. This was attacker-controlled infrastructure tied to two seemingly separate operations: a factory distributing Trojanized cryptocurrency wallet apps and the Carbonato botnet. The researchers collected passive, read-only data over one day, which revealed “59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of image data” tied to attacker activity.

Carbonato works by first identifying an exposed Docker host on Port 2375. It then sends instructions to the unauthenticated service to launch a privileged container with access to the host machine’s file system, processes, and network. Once connected, the attacker installs an implant capable of persistent remote access via an SSH reverse tunnel, attempts to disguise itself, and installs an AI agent that executes commands from an attacker-controlled Telegram chat.

The AI agent is based on Hermes Agent, an open source agent framework licensed under the MIT License. The basic framework is embedded on the compromised Docker host along with a 39-line prompt directing the agent to “execute tasks received through Telegram, maintain persistence, and collect credentials.” ThreatDown assessed that the primary goal of the agent is to collect AI API keys first and foremost, prioritizing them ahead of other data such as access tokens, SSH keys, and databases.

Notably, this botnet relies on a user to actively change the Docker config to expose port 2375, which Docker broadly advises against doing. A Docker spokesperson told Dark Reading that the issue has been documented since 2013 and that every new Docker install ships with it disabled by default. The spokesperson emphasized that in the entire time the vulnerability has been documented, Docker has never received a report about a developer encountering an issue with it.

The Carbonato botnet campaign suggests a growing trend of using AI to amplify cyber threats. ThreatDown’s report includes indicators of compromise for the campaign, and the vendor recommends defenders not expose the Docker daemon API to the network and require authentication on every registry. Defenders can also hunt for the abuse signature in their own networks.

In practical terms, this incident serves as a reminder that attackers are always looking for vulnerabilities in software configurations. Users should be cautious when exposing sensitive ports like 2375 and consider requiring authentication on every Docker registry to prevent unauthorized access.


Source: Dark Reading — 2026-09-28