Carbonato botnet takes over exposed Docker hosts and installs a rogue AI agent called GH0ST
ThreatDown found the operation's tooling in an unsecured Docker registry, with operational evidence going back to October 2024.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
ThreatDown researchers have described Carbonato, a worm-like botnet that targets Docker daemons whose API is exposed without authentication on port 2375. The malware tells the daemon to launch a privileged container, which gives it access to the host. It then opens a reverse SSH tunnel, installs an SSH server with the operators' key and reports each new infection over Telegram. Scripts using cron, systemd timers, rc.local and OpenRC hooks keep it running. On the compromised hosts, Carbonato installs the Hermes Agent AI framework with an agent named "GH0ST" and replaces the framework's default SOUL.md persona file with the attackers' instructions. ThreatDown found the material in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence covers October 2024 to August 2026. The archive also documented a separate campaign that distributed counterfeit cryptocurrency wallet apps. Security Affairs reports that the botnet steals credentials to fund its own LLM gateway. Organizations running Docker with an open, unauthenticated API are directly exposed. The campaign shows criminals starting to use general-purpose agent frameworks as payloads on compromised machines.