
A newly discovered Docker botnet is implanting AI agents onto compromised hosts in order to send stolen credentials back to the attackers.
ThreatDown researchers recently uncovered Carbonato, a botnet that compromises servers running unauthenticated Docker daemons (the background process that manages Docker containers, images, networks, and related operations) exposed on port 2375, establishes persistence, and spreads to other reachable Docker hosts.
Researchers discovered the botnet last month when they identified an unauthenticated Docker registry that had been publicly exposed since May. This was attacker-controlled infrastructure tied to two seemingly separate operations: a factory distributing Trojanized cryptocurrency wallet apps and the Carbonato botnet.
Across one day of passive, read-only data collection, ThreatDown identified "59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of image data" tied to attacker activity, according to a blog post.
How the Carbonato Botnet Gets its Hooks In
During an attack, the threat actor first identifies an exposed Docker host on Port 2375. Then the Carbonato botnet sends instructions to the unauthenticated service telling it to launch a privileged container with access to the host machine's file system, processes, and network. Once connection is established, the attacker installs an implant capable of persistent remote access (via an SSH reverse tunnel), attempts to disguise itself, and installs an AI agent that executes commands from an attacker-controlled Telegram chat.
The agent is based on Hermes Agent, an open source agent framework from Nous Research that is licensed under the MIT License. This is perhaps the most novel aspect of the botnet. Embedded on the compromised Docker host is the basic framework as well as a 39-line prompt directing the agent to "execute tasks received through Telegram, maintain persistence, and collect credentials," the researchers said.
The agent's primary goal, ThreatDown assessed, is to collect AI API keys first and foremost, prioritizing them ahead of other data such as access tokens, SSH keys, and databases. Separately from the agent, the botnet malware includes more conventional scripts (i.e., not AI-driven) that search nearby networks for other exposed Docker services, compromise additional hosts, and repeat the infection cycle.
ThreatDown did not attribute the campaign to a specific threat actor, though various clues (UTC-6:00 timestamps, the use of voseo Spanish in deployment reports, a possible country calling code in the attacker's Telegram handle) suggest the botnet operators could be based in Costa Rica.
Port 2375: Addressing an Old Docker Problem
It's worth noting that port 2375, which is an unencrypted REST API endpoint for remote connections to the Docker daemon, is not a novel initial access vector. A Docker spokesperson tells Dark Reading that the issue has been documented since 2013, and that every new Docker install ships with it disabled by default. In other words, the botnet attack relies on a user to actively change the Docker config to expose the port, which Docker broadly advises against doing.
"In the entire time the vulnerability has been documented, Docker has never received a report to our security team about a developer encountering an issue with it. In fact, the only reason it's still an option, rather than removed outright, is that we often hear from customers who rely on it for legitimate setups and don't want it taken away entirely," the spokesperson says. "As always, we appreciate the work that goes into keeping the community informed about known vulnerabilities."
ThreatDown's report includes indicators of compromise for the Carbonato botnet campaign. The vendor also recommends defenders not expose the Docker daemon API to the network and to require authentication on every registry. Defenders can also hunt for the abuse signature, check for the botnet's persistence kit, and watch for suspicious network patterns.
Related:Cyera's Oasis Security Buy Is All About AI Agent Control
Organizations should also treat AI API keys like any other sensitive credentials. "The doctrine ranks them first, so inventory where they live, rotate them, and monitor their usage," ThreatDown said.
Dark Reading has reached out to ThreatDown for additional comment.