A new botnet campaign named Carbonato is exploiting a common Docker misconfiguration to hijack servers and turn them into intelligent, AI-powered attack nodes.

According to research reported by BleepingComputer on September 28, 2024, the campaign targets Docker daemon management ports (TCP 2375 or 2376) that are inadvertently exposed to the public internet without authentication. This widespread misconfiguration grants attackers unauthenticated command execution on the host, providing a direct entry point.

Once initial access is achieved, the malware distinguishes itself by installing the Hermes Agent, an open-source AI framework built for autonomous task execution. This transforms a standard bot infection into a more sophisticated compromise, where the AI agent can manage complex post-exploitation activities.

The integration of an AI framework presents elevated risks compared to conventional malware. An adaptive agent can dynamically manage tasks, potentially automate lateral movement, and evade basic detection mechanisms, representing a clear evolution in botnet capabilities.

The attack chain begins with the exposed Docker API, which allows the attacker to spawn malicious containers. These containers then fetch and execute the Carbonato payload, establishing the Hermes Agent on the compromised host. The machine is then conscripted into the botnet, potentially for cryptocurrency mining, DDoS attacks, or further scanning.

For DevOps and security teams, this threat necessitates immediate configuration audits and the adoption of hardened practices:

  • Restrict API Exposure: Audit firewall rules to ensure Docker management ports are never exposed directly to the internet. Access should be limited to trusted networks via a VPN.
  • Enforce TLS Authentication: Configure the Docker daemon to use TLS certificates for encrypted, mutually authenticated connections, securing access even if ports are misconfigured.
  • Apply Least-Privilege RBAC: Implement Role-Based Access Control for the Docker API. Avoid using the root user and create specific accounts with minimal required permissions.
  • Monitor Container Activity: Employ logging and monitoring to detect anomalous container creation, resource spikes, or connections to suspicious external hosts.

The Carbonato campaign highlights the growing convergence of cloud-native vulnerabilities with advanced AI tooling. Securing container environments is now a critical component of proactive cybersecurity strategy.


一個名為 Carbonato 的新僵屍網絡活動正利用常見的 Docker 錯誤配置來劫持伺服器,並將其轉變為智能的、由人工智能驅動的攻擊節點。

根據 BleepingComputer 在2024年9月28日報導的研究,該活動針對那些不慎在未經認證下暴露於公共互聯網的 Docker 守護進程管理端口(TCP 2375 或 2376)。這種普遍的錯誤配置使攻擊者能夠獲得未經認證的主機命令執行權限,提供了一個直接的入侵點。

一旦取得初始訪問權限,該惡意軟件的獨特之處在於安裝了 Hermes Agent,一個專為自主任務執行而建的開源人工智能框架。這將一個標準的殭屍網絡感染轉變為更複雜的入侵行為,人工智能代理器可管理複雜的漏洞利用後活動。

整合人工智能框架所帶來的風險,相較於傳統惡意軟件有所提升。一個自適應代理器可以動態管理任務,可能自動化橫向移動,並規避基本的偵測機制,這代表著僵屍網絡能力的明顯演進。

攻擊鏈始於暴露的 Docker API,攻擊者藉此創建惡意容器。這些容器隨後獲取並執行 Carbonato 有效負載,在被入侵的主機上建立 Hermes Agent。該機器隨後被編入僵屍網絡,可能用於加密貨幣挖礦、DDoS 攻擊或進一步掃描。

對於 DevOps 和安全團隊而言,此威脅要求立即進行配置審計並採取強化措施:

  • 限制 API 暴露: 審計防火牆規則,確保 Docker 管理端口切勿直接暴露於互聯網。訪問應透過 VPN 限制於可信網絡內。
  • 強制使用 TLS 認證: 配置 Docker 守護進程以使用 TLS 證書進行加密、雙向認證的連接,即使端口配置錯誤也能確保訪問安全。
  • 實踐最小權限 RBAC: 為 Docker API 實施基於角色的訪問控制。避免使用 root 用戶,並創建具有最低所需權限的特定帳戶。
  • 監控容器活動: 採用日誌記錄和監控,以偵測異常的容器創建、資源激增或連接至可疑外部主機的行為。

Carbonato 活動突顯了雲原生漏洞與先進人工智能工具日益融合的趨勢。保護容器環境現已成為主動網絡安全策略的關鍵組成部分。

新聞來源 / Original News Source