New Botnet Uses AI Agent to Hijack Exposed Docker Servers
Security researchers have identified a new botnet, dubbed Carbonato, that targets exposed Docker hosts. Rather than relying solely on traditional malware, the attackers install the open source Hermes Agent AI framework on compromised systems, allowing them to issue commands remotely through Telegram.
Once installed, the AI agent is used to steal AI API keys stored on the infected hosts. This gives attackers access to paid AI services at the victim's expense, and potentially exposes sensitive data tied to those accounts. The use of an AI framework to automate command execution marks a shift in how botnets are being built, making them more flexible and harder to detect using standard signatures.
Small businesses running Docker containers, particularly those with management interfaces exposed to the internet, are at risk if these systems are not properly secured. Misconfigured or internet-facing Docker hosts remain a common entry point for attackers scanning for easy targets.