<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx" -->

---
title: New Carbonato malware uses AI agents to hijack exposed...
description: A new botnet malware named Carbonato targets Docker hosts with an unauthenticated API exposed on port 2375, launching privileged containers to gain host...
canonical: https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New Carbonato malware uses AI agents to hijack exposed Docker hosts | daily.dev
og:description: A new botnet malware named Carbonato targets Docker hosts with an unauthenticated API exposed on port 2375, launching privileged containers to gain host...
og:url: https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx
og:image: https://api.daily.dev/og/posts/Y3wkIZGPX.png
og:image:alt: New Carbonato malware uses AI agents to hijack exposed Docker hosts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New Carbonato malware uses AI agents to hijack exposed Docker hosts

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A new botnet malware named Carbonato targets Docker hosts with an unauthenticated API exposed on port 2375, launching privileged containers to gain host access. It installs the Hermes Agent AI framework running an agent named GH0ST, which executes an interactive command loop to steal AI API keys, SSH credentials, and access tokens, and run arbitrary commands via Telegram. The malware sets up reverse SSH tunnels, multiple persistence mechanisms, and worm-like scanning to spread to other exposed Docker hosts. Researchers at Malwarebytes' ThreatDown found evidence spanning October 2024 to August 2026 and point to a possible Costa Rica-based operator. Recommended mitigations include keeping Docker daemon APIs off the network and requiring registry authentication.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts>

## Questions this post answers

### How does Carbonato malware compromise exposed Docker hosts?

Carbonato targets Docker hosts with an API exposed on port 2375 without authentication, connecting to it and instructing the daemon to launch a privileged container that grants host access. It then opens a reverse SSH tunnel, installs an SSH server with the operators' key, and sets up persistence via cron jobs, systemd timers, rc.local, and OpenRC hooks. It reports deployments through Telegram and scans attached networks every five minutes to spread further.

_Teams securing container infrastructure follow emerging Docker attack techniques like this on daily.dev._

### What is the Hermes Agent AI framework and how is it being abused in cyberattacks?

Hermes Agent is an AI agent framework that has been repeatedly abused in malicious operations, including automating an attack on the Thai finance ministry, autonomous server attacks using DeepSeek AI, and a card-skimming campaign that stole 600,000 credit card details. In the Carbonato botnet, it runs as an agent named GH0ST that interprets Telegram-issued tasks, writes terminal commands, reads output, and decides next actions autonomously.

_Security engineers tracking AI agent misuse in real attacks can follow developments like this on daily.dev._

### How can I protect my Docker daemon from being hijacked by botnets like Carbonato?

Keep Docker daemon APIs off the network entirely and require authentication on any container registries, since Carbonato specifically exploits Docker APIs exposed on port 2375 without authentication. Warning signs of compromise include a GH0ST persona file, a CARBONATO_API_KEY setting, unexpected Telegram traffic, and reverse SSH tunnels connecting to AS262145.

_Ops teams hardening Docker deployments against exposure use daily.dev to stay ahead of new attack patterns._

## Similar posts on daily.dev

- [Agentic threat actor hits the orchestration plane: AI agent-driven container escape](https://daily.dev/posts/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape-j35vuwuki) · Sysdig Blog · 0 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#docker](https://daily.dev/tags/docker), [#containers](https://daily.dev/tags/containers), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New Carbonato malware uses AI agents to hijack exposed Docker hosts","url":"https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx"},"datePublished":"2026-09-24T20:11:12.111Z","dateModified":"2026-09-24T20:11:39.329Z","description":"A new botnet malware named Carbonato targets Docker hosts with an unauthenticated API exposed on port 2375, launching privileged containers to gain host...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/571653804ce7295bcb6492f57616484a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/571653804ce7295bcb6492f57616484a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,docker,containers,malware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New Carbonato malware uses AI agents to hijack exposed Docker hosts"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts-y3wkizgpx#faq","mainEntity":[{"@type":"Question","name":"How does Carbonato malware compromise exposed Docker hosts?","acceptedAnswer":{"@type":"Answer","text":"Carbonato targets Docker hosts with an API exposed on port 2375 without authentication, connecting to it and instructing the daemon to launch a privileged container that grants host access. It then opens a reverse SSH tunnel, installs an SSH server with the operators' key, and sets up persistence via cron jobs, systemd timers, rc.local, and OpenRC hooks. It reports deployments through Telegram and scans attached networks every five minutes to spread further. Teams securing container infrastructure follow emerging Docker attack techniques like this on daily.dev."}},{"@type":"Question","name":"What is the Hermes Agent AI framework and how is it being abused in cyberattacks?","acceptedAnswer":{"@type":"Answer","text":"Hermes Agent is an AI agent framework that has been repeatedly abused in malicious operations, including automating an attack on the Thai finance ministry, autonomous server attacks using DeepSeek AI, and a card-skimming campaign that stole 600,000 credit card details. In the Carbonato botnet, it runs as an agent named GH0ST that interprets Telegram-issued tasks, writes terminal commands, reads output, and decides next actions autonomously. Security engineers tracking AI agent misuse in real attacks can follow developments like this on daily.dev."}},{"@type":"Question","name":"How can I protect my Docker daemon from being hijacked by botnets like Carbonato?","acceptedAnswer":{"@type":"Answer","text":"Keep Docker daemon APIs off the network entirely and require authentication on any container registries, since Carbonato specifically exploits Docker APIs exposed on port 2375 without authentication. Warning signs of compromise include a GH0ST persona file, a CARBONATO_API_KEY setting, unexpected Telegram traffic, and reverse SSH tunnels connecting to AS262145. Ops teams hardening Docker deployments against exposure use daily.dev to stay ahead of new attack patterns."}}]}
```

