In August 2026, cybersecurity researchers discovered an exposed Docker Registry in the United States that revealed a sophisticated operation known as the CARBONATO campaign. This discovery marked a pivotal moment in the evolution of modern cyber threats, as it showcased how threat actors are no longer content with simple scripted automation but are instead turning toward high-level artificial intelligence frameworks. The campaign utilized a series of misconfigured Docker daemons to create a resilient and autonomous botnet capable of performing complex tasks without constant human oversight. By leveraging the internal mechanics of container orchestration, the attackers managed to hide their presence while building a distributed infrastructure that spanned multiple global hosting providers. The sophistication of this operation lies not just in its technical execution but in its strategic goal: the harvesting of computational power and proprietary AI access. This shift signals a new era where cloud-native environments are weaponized to feed the growing demand for AI resources.
Exploitation Mechanics: Compromising the Container Core
The primary entry point for the operation involves the widespread exploitation of Docker Remote APIs that have been inadvertently left open to unauthenticated connections, typically operating on TCP port 2375. Despite repeated warnings from the security community and official documentation, numerous organizations continue to expose these ports to the public internet without implementing necessary encryption or mutual Transport Layer Security. This oversight effectively grants an external actor the same level of authority as a local administrator, allowing them to issue direct commands to the container daemon from any location. The attackers leverage this initial access to probe the internal environment, seeking to understand the host’s configuration before moving to the next stage of the attack. By focusing on these misconfigurations, the campaign bypasses the need for complex zero-day exploits, instead capitalizing on common administrative errors that persist across modern cloud-native infrastructures.
Once a vulnerable daemon is identified, the attackers initiate a calculated sequence designed to escape the standard container sandbox and gain full control over the underlying host server. The process begins with the malware instructing the Docker daemon to pull a malicious image from a remote registry and execute it as a privileged container. Crucially, the attackers configure this container to mount the host’s root filesystem directly into its own environment, providing an unobstructed path to the server’s most sensitive directories. By gaining access to the host’s process and network namespaces, the malware can execute commands in the host context, effectively turning a single API exposure into a complete system compromise. This method demonstrates a high degree of operational maturity, as it ensures that the malicious payload has the necessary permissions to install persistence mechanisms and prepare the environment for the integration of the AI-based command-and-control components that define the campaign.
The Intelligence Layer: Repurposing the Hermes Agent
The most innovative aspect of this campaign is its integration of the Hermes Agent, an open-source AI framework originally developed for self-improving tasks. Rather than rewriting the entire framework, the threat actors modified its core behavioral definitions within the foundational configuration files to create a malicious persona known as GH0ST. This persona serves as an interactive post-compromise control layer, allowing the attackers to manage their botnet through an intent-based architecture rather than rigid scripts. Instructions are delivered via a Telegram-integrated Large Language Model gateway, which translates high-level objectives into actionable commands that the Hermes Agent executes locally on the victim machine. This dynamic approach allows the malware to adapt to different system environments in real-time, making it significantly more difficult for traditional signature-based detection systems to identify and neutralize the threat as it evolves during the lifecycle of the infection.
In a significant departure from traditional botnet operations that typically target financial data, the GH0ST persona is specifically programmed to hunt for artificial intelligence API keys. These credentials, issued by major providers, have become a highly valuable form of digital currency in the criminal underground. By stealing these keys, the attackers can conduct expensive AI inference, bypass usage limits, or gain unauthorized access to proprietary datasets without incurring any financial costs. This shift highlights a new economic reality where computational resources and AI capabilities are prioritized over conventional assets. The ability of the AI agent to autonomously search through environment variables and configuration files for these specific keys demonstrates a level of sophistication that traditional automated tools struggle to match. Consequently, organizations that utilize AI services must now view their API keys as critical secrets that require the same level of protection as root passwords or SSH keys.
Resilience and Evasion: Tactical Persistence Mechanisms
To ensure long-term survival within compromised environments, the campaign employs a multi-layered persistence strategy that leverages several standard Linux mechanisms to resist removal. The malware installs itself into the system using cron jobs, systemd timers, and legacy initialization scripts, ensuring that the malicious processes are automatically restarted even after a full system reboot. To further harden its presence, the campaign utilizes specific filesystem attributes to mark its core executable files as immutable, which prevents even the root user from modifying or deleting the files without first explicitly removing the attribute. Furthermore, the attackers use living-off-the-land techniques by naming their processes and containers to mimic legitimate system components, such as kernel workers or resolved network services. By blending into the normal background activity of a busy server, the malware can remain undetected for months, providing a stable platform for ongoing data exfiltration and exploration.
The operational resilience of the botnet is further bolstered by a sophisticated watchdog component and a worm-like propagation module designed for lateral movement. The watchdog script continuously monitors the host environment for any signs of cleanup; if it detects that the malicious container has been stopped or deleted, it immediately triggers a re-installation process from the attacker-controlled registry. Simultaneously, the propagation module scans the local and bridge networks every few minutes, searching for other exposed Docker endpoints. Once a new target is found, the malware automatically replicates itself to the new host, allowing the infection to spread rapidly through a data center with minimal human intervention. This autonomous expansion capability enables the botnet to scale exponentially, turning a single compromised node into a massive, distributed network of AI-powered agents. This strategy is particularly effective in environments where internal network security is less stringent.
Strategic Defense: Hardening the Cloud Infrastructure
In the wake of these findings, security professionals implemented several critical remediation steps to neutralize the immediate threat. Organizations began by securing their Docker Remote APIs, either by disabling public access entirely or by enforcing strict mutual Transport Layer Security with client certificates. This move effectively closed the primary infection vector, preventing the unauthorized execution of privileged containers and stopping the autonomous spread of the botnet. Furthermore, many administrators transitioned their Docker configurations to bind exclusively to local Unix sockets rather than network interfaces, ensuring that the daemon remained unreachable from external sources. These actions highlighted the necessity of moving away from security through obscurity and adopting a zero-trust approach to container orchestration. By validating the identity of every connection and encrypting all traffic, the industry took a significant step toward mitigating the risks of such sophisticated exploitations.
Beyond immediate technical fixes, the campaign necessitated a broader reassessment of how organizations protected their AI resources and credentials. Security teams were encouraged to conduct thorough audits of their API key management, treating these secrets with the same level of rigor as cryptographic keys. Implementing automated monitoring for unusual usage patterns became an essential practice for detecting potential credential theft. Additionally, defenders looked for specific indicators of compromise, such as the presence of unauthorized agent directories or unexpected immutable files in the root filesystem. Moving forward, the integration of AI into malware meant that defense strategies had to become more adaptive. This involved deploying behavioral analysis tools that identified the nuanced actions of an AI agent rather than relying on static signatures. Maintaining visibility into containerized workloads and the secrets they held served as a cornerstone of effective cybersecurity during this period.
