ALEXKRI.NET
Resume Contact
← Back

New Carbonato malware uses AI agents to hijack exposed Docker hosts

An exposed Docker daemon on port 2375 with no auth is a decade-old mistake. The payload is what is new: Carbonato drops an AI agent - Hermes framework, persona “GH0ST” - that takes tasks over Telegram, hunts API keys and SSH credentials, and runs shell commands on request. It rescans attached networks every five minutes. ThreatDown found the crew’s own unauthenticated registry: ~60 repos, 4.3 GB, activity back to October 2024.

Read the source ↗