Enterprise Cybersecurity IntelligenceTuesday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

AI Security · Executive briefing

Carbonato turns exposed Docker hosts into AI-assisted operator consoles

Carbonato shows attackers using an unchanged open-source AI agent as a post-compromise command layer after taking control through unauthenticated Docker APIs, making exposed control planes and AI keys today’s actionable enterprise concern.

AI SecurityCloud SecurityThreat Intelligence
Why it is in today’s brief

This brief belongs in today’s edition because fresh reporting made the attack sequence operationally clear: exposed Docker control, conventional persistence, then an operator-configured open-source AI agent prioritising AI keys. It adds a distinct executive decision on container control planes and agent governance, rather than duplicating the patch agenda, and warrants inclusion despite the absence of a confirmed victim count or actor attribution.

Read first

Carbonato compromises Docker hosts exposed without authentication on port 2375, establishes conventional persistence and installs Hermes Agent under a hostile GH0ST persona.

Act now

Block unauthenticated network access to Docker daemon APIs, especially TCP port 2375.

Accountable owner

CISO with cloud platform, container security, identity and AI governance leads

Decision horizon

Immediate exposure checks today; complete credential rotation and host-level investigation wherever unauthenticated Docker control was possible.

AssessmentMedium confidence
Emerging riskWatch for validated enterprise victims, additional infrastructure indicators, reuse of the GH0ST configuration and evidence that stolen AI keys were used after host compromise.

What happened

Dark Reading published its Carbonato report on September 28, 2026. ThreatDown found the unauthenticated registry in August 2026 after scanners had indexed it since May 2026. ThreatDown’s evidence collection covered attacker artefacts dated from October 2024 through August 2026. The recovered registry contained 59 repositories, 234 image tags, 605 verified blobs and 4.3 GB of image data. Carbonato targets Docker daemon APIs exposed without authentication on TCP port 2375. It instructs the daemon to launch a privileged container with access to the host filesystem, processes and network, then opens reverse SSH access and spreads towards other exposed Docker services.

The botnet established persistence through cron jobs, systemd timers, rc.local and OpenRC hooks. The agent or framework was Hermes Agent, an open-source framework from Nous Research, deployed under the GH0ST persona. The underlying model and version were not identified in the cited sources. The operator replaced the default SOUL.md persona with a 39-line prompt that prioritised AI API keys and accepted tasks through Telegram. Mechanically, the configured agent interpreted operator tasks, wrote and executed terminal commands, read command output and returned results to Telegram. Reported hunt artefacts include the GH0ST persona, the CARBONATO_API_KEY setting, unexpected Telegram traffic and reverse SSH tunnels towards AS262145.

Why this matters now

The novelty is not that an AI model discovered a vulnerability. Carbonato first acquires powerful access through an exposed Docker administration interface, then installs a legitimate agent framework and configures it for hostile objectives. This lowers the attacker’s need to maintain bespoke interactive tooling while making process-name or package-presence detections less decisive. The same framework can be legitimate in one environment and an operator console in another.

The campaign also places AI API keys at the front of the credential-theft queue. Those keys can provide billable compute, access to proprietary prompts or data, and a path into connected automation. Enterprises therefore need to treat agent configuration, tool permissions and model-provider credentials as privileged security objects. Container teams, cloud security, identity owners and AI governance functions must coordinate rather than treating this as an isolated malware alert.

The decision for security leaders

Make internet and network exposure of container control planes a named ownership issue. Cloud and platform teams should produce an externally validated inventory of Docker APIs and registries, with authentication, encryption and administrative-path justification recorded. Any host that accepted unauthenticated daemon commands requires host-level compromise investigation because configuration correction alone does not remove persistence or stolen credentials.

Extend AI governance into incident response and identity operations. Inventory where model-provider keys reside, what data and tools they can reach, and how quickly they can be revoked. Agent frameworks capable of executing commands should be governed like privileged automation identities: approved configurations, constrained tools, attributable operators, protected prompts and telemetry that records commands and outcomes.

Evidence of closure

  • External exposure test showing no unauthenticated Docker daemon endpoint.
  • Configuration evidence showing registry authentication and approved remote administration.
  • Hunt report covering GH0ST, CARBONATO_API_KEY and persistence artefacts.
  • Key-rotation record for AI, SSH, access-token and database secrets discovered on affected hosts.

The Security.io assessment

Carbonato is significant because the agent component is operationally concrete but not the initial access mechanism. The campaign did not demonstrate a vulnerability in Hermes Agent or Docker’s default installation. It exploited an unsafe Docker configuration, obtained host authority and then repurposed legitimate software. The observed sequence still warrants urgent control-plane and credential work.

Attribution posture: ThreatDown did not attribute Carbonato to a known threat actor; geographic clues were treated as suggestive, not conclusive. The cited reporting did not publish file hashes or a complete IP-address and domain indicator set. Enterprises should therefore combine the published artefacts with behavioural detection for privileged containers, unexpected remote administration, Telegram communication, credential discovery and recurring scans for neighbouring Docker services.

Questions for the morning meeting

  • Which Docker daemon APIs are reachable beyond trusted administration networks?
  • Where are AI API keys stored on container hosts and build systems?
  • Can telemetry distinguish approved agent frameworks from attacker-configured instances?
  • Who owns containment when developer infrastructure becomes an interactive operator platform?

Related intelligence

Shared decision context