A new botnet is closing the loop on cybercrime economics by using stolen credentials not as the end product, but as operational fuel to pay for its own large language model (LLM) gateway. The CARBONATO botnet, active since at least October 2024, demonstrates a resilient threat model where credential theft directly powers enhanced offensive capabilities.

The operation was uncovered by ThreatDown researchers after discovering an unauthenticated Docker container registry exposed to the internet. The registry contained the attackers' entire toolchain, offering a clear view of the attack chain.

The campaign exploits a prevalent and preventable weakness: Docker daemons exposed to the internet without authentication. Upon initial access, CARBONATO deploys a containerized AI agent. This agent autonomously traverses the network to harvest API keys and credentials.

These stolen keys—for cloud platforms and AI services—are the key innovation. Instead of being sold, they are immediately injected into CARBONATO's infrastructure to fund access to legitimate LLM gateways. This grants the botnet access to powerful language models, which it uses to improve reconnaissance, identify high-value targets, and execute complex commands autonomously.

This model represents a dangerous fusion of traditional infrastructure misconfiguration and weaponized AI. It moves the concept of AI-powered malware from theory to operational practice, framing credential theft as a means to acquire computational resources for the attacker.

To defend against this specific campaign and the broader model it represents, organizations must take decisive action:

  1. Harden Docker Daemons: Enforce authentication on all Docker daemons. Never expose the Docker API to the public internet without strict access controls and TLS.
  2. Secure Registries: Implement access controls on container registries to prevent the leakage of images and toolchains.
  3. Monitor for Anomalies: Deploy runtime security to detect unusual behavior, such as unexpected credential harvesting or network activity from containers.

The CARBONATO botnet illustrates a shift where adversaries are building self-funding, AI-enhanced attack loops. Its emergence underscores that securing API keys and cloud configurations is now a critical frontline in cybersecurity.


一個新型僵屍網絡正透過利用被竊取的憑證作為營運燃料(而非最終產品),來支付其自身的大型語言模型(LLM)網關費用,從而完善網絡犯罪經濟學。名為 CARBONATO 的僵屍網絡自2024年10月起一直活躍,展示了一種具韌性的威脅模式,其中憑證竊取直接驅動其增強的攻擊能力。

ThreatDown 研究人員在發現一個暴露於互聯網且未經身份驗證的 Docker 容器倉庫後,揭露了此行動。該倉庫包含攻擊者的整個工具鏈,清晰展示了整條攻擊鏈。

此活動利用了一個普遍且可預防的弱點:暴露於互聯網且未經身份驗證的 Docker 守護進程。在初始入侵後,CARBONATO 部署一個容器化 AI 代理。該代理會自主遍歷網絡以收集 API 密鑰和憑證。

這些被竊取的密鑰——用於雲平台和 AI 服務——是關鍵的創新之處。它們並非被出售,而是立即注入 CARBONATO 的基礎設施中,用以資助對合法 LLM 網關的訪問。這使該僵屍網絡得以存取強大的語言模型,用於改進偵察工作、識別高價值目標,以及自主執行複雜指令。

此模式代表了傳統基礎設施配置錯誤與武器化 AI 的危險融合。它將 AI 驅動惡意軟件的概念從理論推向實際操作,將憑證竊取定位為攻擊者獲取運算資源的手段。

為防禦此特定活動及其代表的更廣泛模式,各組織必須採取果斷行動:

  1. 加固 Docker 守護進程: 對所有 Docker 守護進程強制執行身份驗證。切勿在未經嚴格訪問控制和 TLS 的情況下,將 Docker API 暴露於公共互聯網。
  2. 保護倉庫安全: 在容器倉庫上實施訪問控制,以防止鏡像和工具鏈洩露。
  3. 監控異常行為: 部署運行時安全措施以偵測異常行為,例如來自容器的意外憑證收集或網絡活動。

CARBONATO 僵屍網絡說明了一種趨勢:對手正在構建自我資助、AI 增強的攻擊循環。其出現強調了確保 API 密鑰和雲配置安全現已成為網絡安全的關鍵前線。

新聞來源 / Original News Source