⚠️ Region Alert: UAE/Middle East
Cybersecurity researchers have identified a new botnet malware named Carbonato that targets unauthenticated Docker daemons on port 2375 to deploy the Hermes Agent AI framework. This malware exhibits worm-like behavior, propagating through neighboring networks and establishing persistence via privileged containers and reverse SSH tunnels. Once installed, it utilizes a custom AI persona named "GH0ST" to execute tasks received via Telegram, effectively turning compromised hosts into autonomous hacking nodes capable of credential theft and further exploitation.
The rise of Carbonato highlights a growing trend in AI-automated cyberattacks. Other observed campaigns involve the use of frameworks like DeepSeek and Hermes to automate target enumeration and exploitation. Notably, Chinese-speaking threat actors have been linked to large-scale operations against online retailers, resulting in the theft of over 600,000 credit card details from victims globally, including those in the U.A.E. and Saudi Arabia, demonstrating the high efficiency and low cost of AI-driven offensive operations.
Additionally, a new Go-based Windows implant called CLOSEDQUORUM has emerged, which employs a quorum-based decision-making system involving multiple LLMs like Alibaba Qwen and Google Gemini. By autonomously determining the next course of action during post-exploitation—such as process hollowing or Early Bird APC injection—these tools significantly reduce the need for manual attacker intervention, allowing threats to move at a speed that challenges traditional security stacks.
Top comments (0)