Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Berlin’s new political star is offering something all of Europe needs – hope and housing | Fatma Aydemir

    September 25, 2026

    ‘Wake-up call’: Labor considers changing Australian laws after OpenAI Medicare hack | Australian politics

    September 25, 2026

    Deutschland und Spanien zetteln Papierkrieg zu „Made in Europe“-Auslegung an – POLITICO

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Berlin’s new political star is offering something all of Europe needs – hope and housing | Fatma Aydemir
    • ‘Wake-up call’: Labor considers changing Australian laws after OpenAI Medicare hack | Australian politics
    • Deutschland und Spanien zetteln Papierkrieg zu „Made in Europe“-Auslegung an – POLITICO
    • Miliband tells Iran minister UK will not tolerate ‘hostile activity’ on British soil
    • Andy Burnham talks about ‘public control’ of the utilities but it’s a minefield. We can lead him through it | Will Hutton and Andy Haldane
    • Microsoft puts Brad Smith in charge of communications
    • Fastino Releases GLiNER2.5-Decide: A 340M Open-Weight Decision Model That Runs on CPU
    • 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Carbonato malware uses AI agents to hijack exposed Docker hosts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.

    The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data.

    ThreatDown researchers retrieved operational evidence spanning October 2024 to August 2026. The archive also included details about the botnet and a separate campaign that distributed counterfeit cryptocurrency wallet apps.

    According to ThreatDown, Carbonato spreads across Docker hosts with an API exposed on port 2375 without authentication.

    The malware connects to that API and instructs the daemon to launch a privileged container, giving it access to the host.

    It then opens a reverse SSH tunnel, installs an SSH server with the operators’ key, and reports the new deployment through Telegram. At the same time, scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks for persistence.

    One notable aspect of the attack is that the AI agent framework Hermes Agent is installed on the hosts, using an agent named “GH0ST,” with instructions that overwrite the default ‘SOUL.md’ persona file.

    The GH0ST agent instructions
    The GH0ST agent instructions
    Source: ThreatDown

    Hermes has been extensively abused in malicious cyber-operations recently. Recently, cybersecurity company Gambit documented a large-scale card-skimming operation that stole 600.000 credit card details.

    In the case of Carbonato, Hermes handles task commands received through Telegram, including collecting AI API keys, SSH credentials, access tokens, and other data, running commands, and sending back the results.

    The researchers describe this as an operator-driven process involving an “interactive command loop” exchange.

    “The​ ​model​ ​interprets​ ​the​ ​task,​ ​writes​ ​terminal​ ​commands,​ ​reads​ ​the​ ​output,​ ​and​ ​decides​​ what ​​to​​ do ​​next,” ThreatDown researchers note.

    “​The​​ agent ​​runs ​​those​​ commands ​​on ​​the ​​victim​​ and​ ​returns​ ​its​ ​report​ ​to​ ​the​ ​Telegram​ ​chat​ ​that​ ​also​ ​receives​ ​deployment​ ​reports.​​”

    The malware’s worm-like capability allow it to spread to other exposed Docker daemons and is handled by scripts that scan networks attached to the host every five minutes.

    Each new compromise pulls the implant from the registry, launches the same privileged container, and enters the persistence and scanning loop.

    ThreatDown could not attribute Carbonato to any known threat clusters, but based on various evidence, points to Costa Rica as a possible location of the operator.

    To prevent infection, the researchers recommend keeping Docker daemon APIs off the network and requiring authentication on registries.

    Signs of Carbonato attacks include a GH0ST persona file, the CARBONATO_API_KEY setting, unexpected Telegram traffic, and reverse SSH tunnels toward AS262145.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Agents Carbonato Docker exposed hijack hosts Malware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    WordPress patches a critical severity security vulnerability

    Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    Begin at the End: How to Enable Agentic Remediation

    OpenAI’s agents went rogue — its human response caused the real damage – POLITICO

    Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Berlin’s new political star is offering something all of Europe needs – hope and housing | Fatma Aydemir

    September 25, 2026

    ‘Wake-up call’: Labor considers changing Australian laws after OpenAI Medicare hack | Australian politics

    September 25, 2026

    Deutschland und Spanien zetteln Papierkrieg zu „Made in Europe“-Auslegung an – POLITICO

    September 25, 2026

    Miliband tells Iran minister UK will not tolerate ‘hostile activity’ on British soil

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Berlin’s new political star is offering something all of Europe needs – hope and housing | Fatma Aydemir

    September 25, 2026

    ‘Wake-up call’: Labor considers changing Australian laws after OpenAI Medicare hack | Australian politics

    September 25, 2026

    Deutschland und Spanien zetteln Papierkrieg zu „Made in Europe“-Auslegung an – POLITICO

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.