A novel botnet is leveraging an AI agent to automate the hijacking of insecure Docker environments, turning compromised cloud hosts into cryptomining infrastructure. Security researchers have uncovered the "Carbonato" malware, which specifically hunts for Docker daemon APIs exposed on the public internet.

The attack exploits a critical yet common misconfiguration: Docker management interfaces left open on ports 2375 or 2376 without authentication. Upon discovering a vulnerable host, the malware deploys its core component—an AI framework dubbed the "Hermes Agent." This agent takes control of the attack lifecycle, autonomously handling steps like reconnaissance, deploying a cryptocurrency miner, and establishing persistence mechanisms on the host system.

The integration of AI represents an evolution in botnet sophistication, moving beyond static scripts. The Hermes Agent is designed to make decisions, allowing it to adapt to different host environments and potentially evade detection more effectively. This autonomous capability highlights a shift toward more resilient, adaptive threats that can optimize attacks in real-time.

The incident underscores a fundamental principle of container security: isolation begins at the host level. Exposing the Docker API effectively bypasses container safeguards, granting attackers root-level control over the Docker engine. They can create malicious containers, access host file systems, and commandeer all available resources for their own use. This flaw is a stark reminder of the shared responsibility model in cloud security, where user misconfigurations can nullify platform protections.

Defending against such threats requires immediate and basic security hygiene. Organizations must immediately audit all infrastructure to identify any Docker API services listening on public interfaces. The Docker daemon socket or API port should never be exposed directly to the internet; access must be restricted to secure, private networks. Where remote access is operationally necessary, strict mutual TLS authentication must be enforced. Furthermore, deploying runtime container security solutions can help detect anomalous behavior, such as unexpected resource spikes or unauthorized container creation, which may signal a compromise.

The emergence of AI-driven tools like Carbonato marks a significant step in automated cybercrime. For the DevOps and security community, it reinforces that foundational configuration management and continuous monitoring are non-negotiable pillars of operational resilience in cloud-native architectures.


一個新型殭屍網絡正利用 AI 代理來自動化劫持不安全的 Docker 環境,將被入侵的雲主機轉變為加密貨幣挖礦基礎設施。安全研究人員揭露了「Carbonato」惡意軟件,它專門搜尋暴露在公共互聯網上的 Docker 守護進程 API。

此次攻擊利用了一個關鍵且常見的配置錯誤:Docker 管理接口在未經認證的情況下,直接暴露於公網的 2375 或 2376 端口。一旦發現有漏洞的主機,該惡意軟件便會部署其核心組件——一個名為「Hermes Agent」的 AI 框架。此代理掌控整個攻擊週期,自主處理諸如偵察、部署加密貨幣挖礦程序,以及在主機系統上建立持久化機制等步驟。

AI 的引入代表了殭屍網絡複雜度的演進,超越了靜態腳本。Hermes Agent 被設計成能自主決策,使其能夠適應不同的主機環境,並可能更有效地規避檢測。這種自主能力凸顯了威脅正朝向更具韌性、更能適應實時優化攻擊的趨勢轉變。

此次事件凸顯了容器安全的一項基本原則:隔離始於主機層級。暴露 Docker API 實質上繞過了容器安全防護,賦予攻擊者對 Docker 引擎的 root 級別控制權。他們可以創建惡意容器、訪問主機文件系統,並挪用所有可用資源。這一漏洞鮮明地提醒了雲安全中的共同責任模型——用戶的配置錯誤可能使平台保護措施失效。

防禦此類威脅需要立即採取基本的安全衛生措施。組織必須立即審計所有基礎設施,以識別任何監聽公共接口的 Docker API 服務。Docker 守護進程套接字或 API 端口不應直接暴露於互聯網;訪問必須限制在安全、私有的網絡範圍內。若因運營需要必須遠程訪問,則必須強制執行嚴格的雙向 TLS 認證。此外,部署運行時容器安全解決方案有助於檢測異常行為,例如未預期的資源飆升或未經授權的容器創建,這些可能預示著系統已被入侵。

像 Carbonato 這類 AI 驅動工具的出現,標誌著自動化網絡犯罪的一個重要里程碑。對於 DevOps 和安全社群而言,這再次強調了基礎配置管理和持續監控是雲原生架構中運營韌性不可或缺的支柱。

新聞來源 / Original News Source