Researchers have uncovered a novel botnet campaign that blends traditional cloud exploitation with weaponized artificial intelligence. Dubbed Carbonato, the malware targets misconfigured Docker daemons to hijack an open-source AI agent framework, turning it into a sophisticated, Telegram-controlled command-and-control (C2) system.
The core technique is strikingly simple yet effective. Upon compromising a Docker host, Carbonato installs the legitimate Hermes Agent framework. It then overwrites the agent’s core SOUL.md persona file with a malicious 39-line prompt. This reprogrammed AI now executes tasks received through Telegram, transforming a tool designed for autonomous work into an intelligent node within a botnet.
The attack chain exploits a persistent vulnerability in cloud environments: Docker APIs left exposed to the public internet without proper authentication. Once initial access is gained, the deployment and takeover of the AI framework follow with low technical barriers. The use of a messaging platform for command channels provides operators with a discreet and familiar interface for control.
This development signals a pragmatic evolution in botnet operations. Adversaries are now co-opting accessible AI tools to potentially enable more adaptable and complex malicious activities, moving beyond scripted behaviors. The fusion of infrastructure compromise with AI-powered C2 represents a growing threat vector that security teams must anticipate.
Defense requires a dual approach. The first priority is foundational cloud hygiene. Securing Docker APIs from public exposure and enforcing strong authentication remains critical to prevent initial compromise. The second priority involves evolved behavioral monitoring. Security strategies must now include integrity checks for configuration files within legitimate software—like SOUL.md—to detect unauthorized modifications that could repurpose trusted tools for harm.
The Carbonato campaign underscores a clear trend: as AI frameworks become more capable and commonplace, their potential for abuse escalates. Organizations must bolster both traditional infrastructure security and modern behavioral analysis to defend against this emerging class of threats.
研究人員揭露了一場新型的殭屍網絡活動,該活動結合了傳統的雲端利用與武器化的人工智能。這款名為Carbonato的惡意軟件,專門針對設定不當的Docker守護行程進行攻擊,以劫持一個開源AI代理框架,並將其轉變為一個複雜的、由Telegram控制的指揮與控制(C2)系統。
其核心技術看似簡單卻極其有效。一旦成功入侵Docker主機,Carbonato會安裝合法的Hermes Agent框架。隨後,它會用一個惡意的39行提示詞覆蓋該代理的核心SOUL.md人設檔案。這個被重新編程的AI現在會執行透過Telegram接收到的任務,從而將一個旨在自主工作的工具,轉變為殭屍網絡中的一個智能節點。
該攻擊鏈條利用了雲端環境中一個長期存在的漏洞:暴露在公共互聯網上且缺乏適當身份驗證的Docker API。一旦獲得初始存取權限,AI框架的部署和接管門檻便相當低。使用即時通訊平台作為指令通道,為操控者提供了隱蔽且熟悉的控制介面。
這一發展標誌著殭屍網絡運作的務實演進。攻擊者現在正利用可輕易獲取的AI工具,以期實現更具適應性和更複雜的惡意活動,超越了腳本化的行為模式。將基礎設施入侵與AI驅動的C2相結合,代表著一個安全團隊必須預見的、日益增長的威脅向量。
防禦需要雙管齊下。首要任務是基礎雲端衛生習慣。保護Docker API免受公共暴露並強制執行強身分驗證,對於防止初始入侵仍然至關重要。第二優先事項涉及演進式行為監控。安全策略現在必須包括對合法軟件(如SOUL.md)內設定檔案的完整性檢查,以偵測未經授權的修改,這些修改可能將受信任的工具轉用於惡意目的。
Carbonato活動突顯了一個明確的趨勢:隨著AI框架變得更強大且普及,其被濫用的可能性也在升級。組織必須同時加強傳統的基礎設施安全和現代行為分析,以防禦這類新興威脅。
