Security researchers at Malwarebytes have identified a novel botnet malware called Carbonato that specifically targets Docker hosts with exposed APIs. The malware was found in an unauthenticated Docker registry containing nearly 60 repositories and 4.3 GB of image data, with operational evidence spanning from October 2024 to August 2026.
Carbonato spreads by connecting to Docker daemons with their API exposed on port 2375 without authentication. It instructs the daemon to launch a privileged container, granting the attacker host-level access. From there, it opens a reverse SSH tunnel, installs an SSH server with the operators' key, and reports new deployments via Telegram. Persistence is maintained through cron jobs, systemd timers, rc.local, and OpenRC hooks.
A notable feature of Carbonato is its use of the Hermes Agent AI framework, which has been increasingly exploited in malicious cyber-operations. The malware installs an agent named 'GH0ST' with instructions that overwrite the default 'SOUL.md' persona file. The AI agent handles commands received through Telegram, including collecting AI API keys, SSH credentials, and access tokens, running commands, and returning results. Researchers describe this as an operator-driven 'interactive command loop' where the model interprets tasks, writes terminal commands, reads output, and decides next actions.
The malware also exhibits worm-like capabilities, scanning networks attached to the infected host every five minutes for other exposed Docker daemons. Each new compromise pulls the implant from the registry, launches the same privileged container, and repeats the persistence and scanning loop.
ThreatDown could not attribute Carbonato to any known threat clusters but pointed to Costa Rica as a possible location of the operator based on various evidence. To prevent infection, researchers recommend keeping Docker daemon APIs secured and not exposing them without authentication.