Forensic Summary
A newly identified botnet malware called Carbonato exploits unauthenticated Docker API endpoints to install the Hermes Agent AI framework, enabling operator-controlled autonomous command execution on compromised hosts. The AI agent, configured under the persona 'GH0ST', operates via an interactive Telegram-driven command loop that harvests AI API keys, SSH credentials, and access tokens. This campaign represents a significant escalation in threat actor abuse of legitimate AI agent frameworks as post-exploitation infrastructure.
Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/carbonato-malware-deploys-ai-agents-to-hijack-docker-hosts/
Top comments (0)