Tech News
← Home  ·  All topics

Docker Hosts

1 GoKawiil brief on this topic

Carbonato botnet exploits exposed Docker APIs to deploy Hermes AI agent

Malwarebytes' ThreatDown researchers identified a new botnet, Carbonato, that scans for Docker hosts with unauthenticated APIs on port 2375 and hijacks them via privileged containers. The malware installs SSH backdoors, sets up multiple persistence mechanisms, and deploys the Hermes Agent AI framework under an agent named GH0ST to execute operator commands and exfiltrate credentials and API keys via Telegram. The findings came from an unauthenticated Docker registry containing nearly 60 repositories and 4.3GB of data spanning operations from October 2024 to August 2026.