DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Carbonato Malware Deploys AI Agents to Hijack Docker Hosts

Forensic Summary

A newly identified botnet malware called Carbonato exploits unauthenticated Docker API endpoints to install the Hermes Agent AI framework, enabling operator-controlled autonomous command execution on compromised hosts. The AI agent, configured under the persona 'GH0ST', operates via an interactive Telegram-driven command loop that harvests AI API keys, SSH credentials, and access tokens. This campaign represents a significant escalation in threat actor abuse of legitimate AI agent frameworks as post-exploitation infrastructure.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/carbonato-malware-deploys-ai-agents-to-hijack-docker-hosts/

Top comments (0)