Carbonato captures Docker servers via Telegram. You don't even need a vulnerability to hack

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
538
Reaction score
951
Deposit
0$
The server does not need a software hole if the administrator has left the interface with almost unlimited rights. The ThreatDown team described the Carbonato botnet, which searches for available without authentication Docker demons on TCP port 2375, captures the host and turns it into an AI-controlled node.

To the infrastructure of Carbonato specialists came out in August 2026 through the open Docker Registry, which was available from the Internet at least from May. During the day of passive collection it was possible to get 59 repositories, 234 tags of images, 605 verified objects of data and 4.3 GB of information. The archive covered the period from October 2024 to August 2026 and revealed two related lines: the botnet and the factory of trojanized crypto wallets.

For the first capture, Carbonato does not exploit a separate Docker vulnerability. Through the open API, the botnet launches a privileged container, connects the root file system of the host and the space of the processes and the network, and then executes commands already on the machine itself. Docker directly warns that unprotected remote access to a demon can give extraneous root rights.

After fixing, the script opens a reverse SSH tunnel to a repeater in Costa Rica, adds the key of the intruders and sends information about the new node to Telegram. The container is disguised as systemd-resolved, and the process arguments simulate the kworker system stream. To experience restarts, Carbonato uses cron, systemd, rc.local and OpenRC timers, after which it makes the created files unchanged.


The most unusual part of the chain begins after the capture. The server is placed the usual open Hermes Agent from Nous Research without changes in the source code, but replace its file SOUL.md with instructions of behavior. In the 39-line prompt, the agent receives the name GH0ST, the order to save access and perform the operator's tasks, and the main prey is declared the API keys of the AI services, standing above SSH data, tokens and databases.

Teams come through Telegram, after which Hermes transmits the task together with a malicious person to the operator-controlled lock of language models. The model generates terminal commands, reads the result, and selects the next step, and the agent performs actions on the infected server and returns the report to the same chat. AI here helps at the post-exploitation phase, but is not responsible for the initial capture or distribution.

Carbonato's reproduction is fully automated by conventional scripts. Every five minutes, the infected node goes over connected networks and Docker bridges, scans subnets /24 in search of port 2375, checks the found services and repeats the chain on new hosts. Similar logic of self-proliferation over cloud infrastructure has already appeared in other harmful worms.

Traces in the infrastructure point to the possible communication of operators with Costa Rica, but ThreatDown does not consider a separate sign sufficient for precise attribution. The country is simultaneously indicated by the temporary zone in terms of configurations, Telegram-nick Carbo506 with a phone code +506 and a network where the reverse SSH tunnels converge. As of 3 September, six of the seven known registers and the language models remained available.

To protect ThreatDown advises not to publish Docker APIs on the network without authentication, to close open registers and to check the servers on the characteristic traces of Carbonato. It is not recommended to block Hermes Agent itself, because the project is legitimate. Separately, it is worth inventorying and changing the API keys of AI services if they were stored on the affected nodes, as well as track their further use.
 
Top Bottom