News

New Botnet Hijacks Exposed Docker Hosts With an AI Agent That Steals Keys to Pay for Itself

The CARBONATO botnet takes over Docker hosts with open APIs, installs an AI agent driven over Telegram, and ranks stolen AI API keys first to fund its operators' own LLM gateway.

New Botnet Hijacks Exposed Docker Hosts With an AI Agent That Steals Keys to Pay for Itself

A botnet is breaking into misconfigured Docker servers and handing the controls to an AI agent. The malware, which ThreatDown named CARBONATO, installs an LLM-driven assistant that its operators command over Telegram, and the first thing it hunts for is other people's AI API keys.

There is no zero-day here. CARBONATO looks for Docker daemons that expose an unauthenticated API on port 2375, a configuration mistake that is still common. Once it finds one, it launches a privileged container with the host's filesystem mounted, which gives it the whole machine.

From there it digs in. It opens a reverse SSH tunnel to a relay in Costa Rica, using a port derived from an MD5 hash of the victim's IP address, installs SSH with the operators' key, and posts a deployment report to Telegram written in voseo Spanish. It survives reboots through cron, systemd timers, rc.local and OpenRC, marks its files immutable, and disguises its container as systemd-resolved or a kernel worker named [kworker/u2:0].

The unusual part comes next. CARBONATO installs an unmodified copy of Hermes Agent, an MIT-licensed open source agent from Nous Research, and overwrites its persona file so the model calls itself GH0ST. Operators then run an interactive loop over Telegram: the model writes shell commands, reads the output and decides what to do next.

What it takes is ranked, and AI API keys sit at the top, ahead of SSH credentials and other tokens. The loot helps fund the operators' own LLM gateway, Security Affairs reported, so each stolen key pays for the next round of AI-driven intrusions. A worm component scans attached networks every five minutes for new targets.

The operators were not careful with their own infrastructure. ThreatDown found an unauthenticated container registry holding 4.3 GB across 59 repositories, including command-and-control tokens and a shared password for the AI gateway, with evidence running through August 2026. The campaign has been active since at least October 2024, with indicators tied to Costa Rica and AS262145, SecurityWeek noted.

Nobody has pinned CARBONATO on a known APT, and there is no count of how many exposed daemons it actually reached. It joins a growing list of cases where AI agents show up in intrusions, and this one runs on stolen keys and a Docker port that should never have been open.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free