New Carbonato malware uses AI agents to hijack exposed Docker hosts
An exposed Docker daemon on port 2375 with no auth is a decade-old mistake. The payload is what is new: Carbonato drops an AI agent - Hermes framework, persona “GH0ST” - that takes tasks over Telegram, hunts API keys and SSH credentials, and runs shell commands on request. It rescans attached networks every five minutes. ThreatDown found the crew’s own unauthenticated registry: ~60 repos, 4.3 GB, activity back to October 2024.