What happened
Dark Reading published its Carbonato report on September 28, 2026. ThreatDown found the unauthenticated registry in August 2026 after scanners had indexed it since May 2026. ThreatDown’s evidence collection covered attacker artefacts dated from October 2024 through August 2026. The recovered registry contained 59 repositories, 234 image tags, 605 verified blobs and 4.3 GB of image data. Carbonato targets Docker daemon APIs exposed without authentication on TCP port 2375. It instructs the daemon to launch a privileged container with access to the host filesystem, processes and network, then opens reverse SSH access and spreads towards other exposed Docker services.
The botnet established persistence through cron jobs, systemd timers, rc.local and OpenRC hooks. The agent or framework was Hermes Agent, an open-source framework from Nous Research, deployed under the GH0ST persona. The underlying model and version were not identified in the cited sources. The operator replaced the default SOUL.md persona with a 39-line prompt that prioritised AI API keys and accepted tasks through Telegram. Mechanically, the configured agent interpreted operator tasks, wrote and executed terminal commands, read command output and returned results to Telegram. Reported hunt artefacts include the GH0ST persona, the CARBONATO_API_KEY setting, unexpected Telegram traffic and reverse SSH tunnels towards AS262145.
Why this matters now
The novelty is not that an AI model discovered a vulnerability. Carbonato first acquires powerful access through an exposed Docker administration interface, then installs a legitimate agent framework and configures it for hostile objectives. This lowers the attacker’s need to maintain bespoke interactive tooling while making process-name or package-presence detections less decisive. The same framework can be legitimate in one environment and an operator console in another.
The campaign also places AI API keys at the front of the credential-theft queue. Those keys can provide billable compute, access to proprietary prompts or data, and a path into connected automation. Enterprises therefore need to treat agent configuration, tool permissions and model-provider credentials as privileged security objects. Container teams, cloud security, identity owners and AI governance functions must coordinate rather than treating this as an isolated malware alert.
The decision for security leaders
Make internet and network exposure of container control planes a named ownership issue. Cloud and platform teams should produce an externally validated inventory of Docker APIs and registries, with authentication, encryption and administrative-path justification recorded. Any host that accepted unauthenticated daemon commands requires host-level compromise investigation because configuration correction alone does not remove persistence or stolen credentials.
Extend AI governance into incident response and identity operations. Inventory where model-provider keys reside, what data and tools they can reach, and how quickly they can be revoked. Agent frameworks capable of executing commands should be governed like privileged automation identities: approved configurations, constrained tools, attributable operators, protected prompts and telemetry that records commands and outcomes.
Evidence of closure
- External exposure test showing no unauthenticated Docker daemon endpoint.
- Configuration evidence showing registry authentication and approved remote administration.
- Hunt report covering GH0ST, CARBONATO_API_KEY and persistence artefacts.
- Key-rotation record for AI, SSH, access-token and database secrets discovered on affected hosts.
The Security.io assessment
Carbonato is significant because the agent component is operationally concrete but not the initial access mechanism. The campaign did not demonstrate a vulnerability in Hermes Agent or Docker’s default installation. It exploited an unsafe Docker configuration, obtained host authority and then repurposed legitimate software. The observed sequence still warrants urgent control-plane and credential work.
Attribution posture: ThreatDown did not attribute Carbonato to a known threat actor; geographic clues were treated as suggestive, not conclusive. The cited reporting did not publish file hashes or a complete IP-address and domain indicator set. Enterprises should therefore combine the published artefacts with behavioural detection for privileged containers, unexpected remote administration, Telegram communication, credential discovery and recurring scans for neighbouring Docker services.
Questions for the morning meeting
- Which Docker daemon APIs are reachable beyond trusted administration networks?
- Where are AI API keys stored on container hosts and build systems?
- Can telemetry distinguish approved agent frameworks from attacker-configured instances?
- Who owns containment when developer infrastructure becomes an interactive operator platform?