The Carbonato Botnet Is Letting A Machine Do The Herding Now, And I Am Not Pleased

The Carbonato Botnet Is Letting A Machine Do The Herding Now, And I Am Not Pleased

I have been in this field since before your "DevOps engineers" knew what a terminal was. I have seen worms propagate over dial-up at a blistering 14.4 kilobaud. I have watched magnetic tape backups save entire enterprises. And now I am being asked to write about a botnet that uses an artificial intelligence agent to manage its own criminal operations.

We have truly lost the plot.

Here is what happened. The Carbonato botnet is compromising exposed Docker hosts, which frankly deserve everything they get for being left open to the internet like an unlatched gate. Once inside, the wolves are deploying something called the Hermes Agent AI framework, an open-source tool that takes commands via Telegram like some kind of criminal group chat.

The flock does not even know it has been occupied. The wolves are not even present. They have automated the occupation. A machine is doing the herding now.

The primary objective appears to be stealing AI API keys. Think about that. The wolves are using artificial intelligence to steal credentials for more artificial intelligence. It is a recursive nightmare that would have been laughed out of any serious threat modeling session in 1997. Back then, attackers had the common decency to be human and exhausted.

The Sky Pasture angle is central here. Exposed Docker APIs are the hole in the fence that nobody bothered to patch because the Shepherds decided that "containers are inherently modern and therefore safe." They are not safe. Nothing is safe. This is the first lesson.

The Sheep Tunnel infrastructure routes the botnet's communications through layers designed to obscure attribution. Combined with Telegram as a command channel, this is actually quite elegant tradecraft. I resent complimenting it, but intellectual honesty demands I do.

Remediation

Stop leaving Docker APIs exposed to the public internet. This is not a sophisticated recommendation. This is a recommendation I should not have to make in the year we are currently in.

Audit your environments for unauthorized AI frameworks. If something called "Hermes" is running on your infrastructure and you did not put it there, you have fleas.

Rotate your AI API keys immediately. Treat them like passwords, because they are passwords, and the wolves now have automated tools specifically designed to collect them.

Enable proper logging on your container hosts so you can see when an uninvited machine starts issuing commands via a messaging application.

The Electric Fence needs to be checked regularly. Manually. By a human who is paying attention. Not by another AI agent. We have enough of those already.

Stay paranoid, stay patched, and for the love of all things sacred, close your Docker ports.


Original Report: https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts