Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

A new threat actor is leveraging the Carbonato botnet to compromise exposed Docker hosts, deploying the open-source Hermes Agent AI framework to facilitate malicious activity. Security researchers have identified that the botnet scans for vulnerable Docker environments to gain unauthorized access. Once inside, the attackers install the AI agent, which allows them to execute arbitrary commands remotely via Telegram. A primary objective of this campaign is the exfiltration of sensitive AI API keys, which can then be used to access expensive cloud-based AI services at the victim's expense. This incident highlights the growing trend of attackers weaponizing AI frameworks to automate post-exploitation tasks. Security experts urge administrators to secure Docker APIs, implement strong authentication, and monitor for unauthorized container deployments to mitigate the risk of such automated attacks.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
A critical zero-day vulnerability has been discovered in the TDengine time-series database, a platform widely utilized across industrial, Internet of…
As enterprises increasingly integrate autonomous AI agents into their workflows, security experts are raising alarms about the lack of oversight regar…
A popular Chrome extension known as 'Poper Blocker,' which has been downloaded by millions of users, has been identified as spyware. Despite being mar…



