Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » New Carbonato Malware Uses AI Agent to Hijack Exposed Docker Servers

New Carbonato Malware Uses AI Agent to Hijack Exposed Docker Servers

Last updated:September 26, 2026
Human Written
  • A new malware called Carbonato attacks unguarded Docker servers and uses an AI tool to control them.

  • Researchers found an open storage hub holding proof of the attack dating back to October 2024.

  • The malware can find new targets every five minutes, spreading on its own without help from the AI tool.

New Carbonato Malware Uses AI Agent to Hijack Exposed Docker Servers

Attackers keep finding smarter ways to break into servers, even when owners think they’re safe. Security researchers have uncovered a new malware operation named Carbonato.

It targets Docker hosts left open on the internet and uses an AI agent to help run the attack. Once inside, it can steal credentials and spread itself to other unprotected systems.

How Carbonato Breaks Into Docker Servers

Researchers at ThreatDown found the campaign after they spotted an unlocked Docker registry online. This registry held 59 repositories, 234 image tags, and close to 4.3GB of data. The files inside stretched from October 2024 all the way to August 2026. They also linked this stash to a separate scam involving fake crypto wallet apps.

Carbonato looks for Docker daemons that lack a login step, mostly through port 2375. Once it spots a weak server, the malware uses the Docker API to start a powerful container. That container can reach outside its own walls and run commands on the main host.

After breaking in, Carbonato sets up ways to stay hidden and connected. It uses tools like cron, systemd timers, rc.local, and OpenRC to keep itself running. It also opens a reverse SSH tunnel, giving attackers a second path back into the machine. The malware then sends details about each new victim straight to the attackers through Telegram.

Separate scripts, not the AI tool, handle the spreading part of the attack. Every five minutes, these scripts scan nearby networks for other Docker daemons open on port 2375. Whenever they find one, Carbonato copies itself onto that server and starts the cycle again.

An AI Agent Joins the Attack

One of the strangest parts of Carbonato is its use of Hermes Agent. This is an open-source AI tool built by Nous Research. Researchers say the attackers did not change the AI tool itself. Instead, they swapped out its SOUL.md file, which tells the AI agent how to behave. That swap turns the tool into a new version the attackers call GH0ST.

The new instructions tell GH0ST to follow commands sent through Telegram. They also push it to hunt for sensitive data on every machine it touches. This includes AI API keys, SSH login details and other access tokens hidden on the server.

GH0ST can read a task from its operator, then write its own commands to carry it out. It checks the results, decides what to do next and reports back through the same Telegram channel. According to ThreatDown’s report, the AI agent mostly handles tasks after a break-in, not the spreading itself.

This setup shows how attackers can turn helpful, open-source AI tools into weapons. AI agents are also being used on the defensive side, with Google deploying Gemini AI agents to monitor dark web threats for businesses, covering how businesses can use Gemini to monitor emerging threats across the dark web. They do not need to build new malware from scratch. They just need to rewrite the instructions an existing AI agent already follows.

What Server Owners Should Do Now

ThreatDown could not tie Carbonato to any known hacking group with full certainty. Still, some clues point toward Costa Rica. Reverse SSH traffic from infected machines was traced back to a network based there.

Researchers urge companies to stop exposing Docker daemon APIs directly to the open internet. Docker registries should also require a login before anyone can view or pull data from them. These two steps alone would block Carbonato’s main way of getting in.

Admins should also watch for warning signs on their own systems. Unexpected Telegram traffic is one red flag. Unfamiliar reverse SSH connections are another. Files tied to a GH0ST version of Hermes Agent should raise concern right away.

This case shows how attackers now combine older tricks with newer AI tools. Exposed Docker servers, hidden scripts and an AI-driven command system work together here. Carbonato proves that once a server gets compromised, AI agents can help attackers manage it faster.

BleepingComputer independently confirmed the core details of this campaign in its own report. A separate write-up from Threadlinqs Intelligence also documents Carbonato’s Docker targeting and its GH0ST-configured AI agent. Together, these sources back up the main facts in this report.

For now, the safest move is simple. Lock down any Docker daemon that faces the internet. Require logins on registries. Watch closely for strange Telegram or SSH activity on your servers.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.