www.darkreading.com 28 Sept 2026, 20:23 UTC

Carbonato Botnet Hijacks Exposed Docker Servers to Steal AI Keys

Carbonato Botnet Hijacks Exposed Docker Servers to Steal AI Keys
CyberSIXT Evidence Panel Source marked as original reporting

THREATDOWN researchers have identified Carbonato, a botnet targeting Docker servers whose unauthenticated daemon APIs are exposed on port 2375. The campaign was discovered after researchers found an attacker-controlled Docker registry that had been publicly accessible since May. During one day of passive, read-only collection, they identified 59 repositories, 234 image tags, 605 verified blobs and 4.3 GB of image data linked to the activity. The infrastructure was also connected to a separate operation distributing Trojanised cryptocurrency wallet applications.

Carbonato instructs an exposed Docker service to launch a privileged container with access to the host’s files, processes and network. It then installs persistence, including an SSH reverse tunnel, and deploys an AI agent based on Nous Research’s open-source Hermes Agent framework. A 39-line prompt directs the agent to receive and execute tasks through an attacker-controlled Telegram chat, maintain persistence and collect credentials.

ThreatDown assessed that AI API keys are the primary target, followed by access tokens, SSH keys and databases. Conventional malware separately scans for other reachable Docker services and repeats the infection process. The researchers did not attribute the campaign to a specific actor, although clues may point to Costa Rica.

Docker said port 2375 has been a documented risk since 2013 and is disabled by default in new installations; exploitation requires an administrator to expose it. ThreatDown recommends not exposing the Docker daemon API, requiring authentication for registries, using its indicators of compromise to check for persistence and suspicious network activity, and inventorying, rotating and monitoring AI API keys.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline