Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget:网络安全
探索我们的品牌
Dark Reading 资源库
Black Hat 新闻
Omdia 网络安全
广告
通讯订阅
网络安全主题
全球
边缘计算
DR Technology
活动
资源
身份与访问管理安全
网络攻击与数据泄露
漏洞与威胁
威胁情报
新闻
Carbonato 僵尸网络在遭入侵的 Docker 主机上部署 AI 代理
该僵尸网络利用开源 Hermes Agent AI 框架,通过 Telegram 执行命令,并从暴露的 Docker 主机中窃取 AI API 密钥。
Alexander Culafi,Dark Reading 高级新闻撰稿人
2026年9月29日
3分钟阅读
来源:HENGKI LESTIO 通过 GETTY IMAGES 提供
一个新发现的 Docker 僵尸网络正在将 AI 代理植入受损主机,以便将窃取的凭证发送回攻击者手中。
ThreatDown 研究人员最近发现了 Carbonato,这是一个僵尸网络,它会入侵运行未认证 Docker 守护进程(负责管理 Docker 容器、镜像、网络及相关操作的后台进程)的服务器,这些服务暴露在端口 2375 上,建立持久性连接,并传播到其他可达的 Docker 主机。
研究人员在上个月发现了这个僵尸网络,当时他们识别出一个自五月以来就公开暴露的未认证 Docker 注册表。这是由攻击者控制的基础设施,与两个看似独立的操作有关:一个分发特洛伊木马化加密货币钱包应用的工厂,以及 Carbonato 僵尸网络。
在一天的被动、只读数据收集期间,ThreatDown 识别出“59 个仓库、234 个镜像标签、605 个已验证的 blob 和 4.3 GB 的镜像数据”与攻击活动有关,据一篇博客文章称。
相关:微软破坏 EvilTokens 设备代码钓鱼服务
Carbonato 僵尸网络如何建立控制
在攻击过程中,威胁行为者首先识别暴露在端口 2375 上的 Docker 主机。然后,Carbonato 僵尸网络向未认证的服务发送指令,指示其启动一个特权容器,该容器可以访问宿主机的文件系统、进程和网络。一旦连接建立,攻击者安装能够持久远程访问的植入程序(通过 SSH 反向隧道),试图伪装自己,并安装一个 AI 代理,该代理执行来自攻击者控制的 Telegram 聊天中的命令。
该代理基于 Hermes Agent,这是 Nous Research 发布的开源代理框架,采用 MIT 许可证授权。这可能是该僵尸网络最新颖的方面。研究人员表示,嵌入在受损 Docker 主机上的不仅是基本框架,还有一个 39 行的提示词,指示代理“执行通过 Telegram 接收的任务,维持持久性,并收集凭证”。
ThreatDown 评估认为,该代理的首要目标是首先收集 AI API 密钥,优先于其他数据(如访问令牌、SSH 密钥和数据库)。与代理分开的是,僵尸网络恶意软件还包括更传统的脚本(即非 AI 驱动),这些脚本在附近网络中搜索其他暴露的 Docker 服务,入侵更多主机,并重复感染循环。
ThreatDown 并未将该活动归因于特定的威胁行为者,尽管各种线索(UTC-6:00 时间戳、部署报告中使用的 voseo 西班牙语、攻击者 Telegram 句柄中的可能国家区号)表明僵尸网络运营商可能位于哥斯达黎加。
相关:AI 模型评估器 METR 遭遇凭证盗窃和探测
端口 2375:解决旧的 Docker 问题
值得注意的是,端口2375是一个用于远程连接Docker守护进程的未加密REST API端点,它并非一种新颖的初始访问向量。Docker发言人向Dark Reading表示,该问题自2013年起便已记录在案,且每次新安装的Docker默认都会禁用此功能。换句话说,这次僵尸网络攻击依赖于用户主动更改Docker配置以暴露该端口,而Docker广泛建议不要这样做。
“在该漏洞被记录的整个期间,Docker从未收到过安全团队关于开发人员遇到相关问题的报告。事实上,它之所以仍然作为一个选项存在,而不是被完全移除,是因为我们经常听到依赖它进行合法部署的客户的声音,他们不希望它被彻底取消,”该发言人说。“一如既往,我们感谢那些致力于让社区了解已知漏洞所做的工作。”
ThreatDown的报告包含了Carbonato僵尸网络活动的妥协指标。该厂商还建议防御者不要将Docker守护进程API暴露给网络,并要求在每个注册表上实施身份验证。防御者还可以搜寻滥用签名,检查僵尸网络的持久化工具包,并监视可疑的网络模式。
相关:Cyera收购Oasis Security的核心在于AI智能体控制
组织也应像对待其他敏感凭据一样对待AI API密钥。“该准则将其列为首位,因此要清点它们的位置,轮换它们,并监控其使用情况,”ThreatDown表示。
Dark Reading已联系ThreatDown以获取更多评论。
关于作者
亚历山大·库拉菲
Dark Reading高级新闻撰稿人
亚历克斯是一位屡获殊荣的作家、记者和播客主持人,常驻波士顿。他在青少年时期为独立游戏出版物撰稿,积累了初步经验,并于2016年从埃默森学院获得新闻学理学士学位。他曾在VentureFizz、Search Security、Nintendo World Report等媒体上发表过文章。
在Dark Reading,他报道各种网络安全话题,包括网络犯罪生态系统、开源安全以及AI与威胁行为者之间的交集。在业余时间,亚历克斯主持每周的Nintendo播客“Talk Nintendo Podcast”,并从事个人写作项目,包括两本此前自行出版的科幻小说。
他曾获得众多奖项,包括2022年TechTarget年度作家奖,以及在2022年至今期间因报道工作获得的10多项Azbee奖。
希望更多Dark Reading的故事出现在您的Google搜索结果中?
立即添加我们
更多见解
行业报告
云安全现状:最新挑战
组织如何管理事件响应
企业如何开发安全应用程序
深入RSAC 2026:安全领袖揭示重塑防御策略的风险
来自Black Hat USA 2025的必备新闻与见解
获取更多研究
网络研讨会
有效的警报分类:减少噪音并发现真实威胁
2027年网络安全展望
威胁暴露分析:衡量和传达安全风险
基准分数是一个虚假信号
构建有效的红队:超越渗透测试
更多网络研讨会
您可能也喜欢
身份与访问管理安全
身份攻击取代漏洞利用成为勒索软件的首要原因
作者:亚历山大·库拉菲
2026年7月15日
身份与访问管理安全
甲骨文红牛赛车团队加速自动化以提升安全性
作者:阿里尔·沃尔德曼
2026年4月30日
身份与访问管理安全
组织转向单点登录和通行密钥以解决不良密码习惯
作者:内特·纳尔逊
2025年11月13日
身份与访问管理安全
1Password解决关键AI浏览器智能体安全漏洞
作者:阿里尔·沃尔德曼
2025年10月10日
精选内容
查看Black Hat USA 2026大会指南,获取来自展会及关于展会的报道和情报!
编辑推荐
应用安全
“Salesbleed”利用 Salesforce Agent 实现 Slack 网络钓鱼
作者:Nate Nelson
2026年9月24日
阅读时间:6分钟
网络攻击与数据泄露
定义2026年夏季的三大网络威胁
作者:Arielle Waldman
2026年9月24日
应用安全
提示注入漏洞击中价值40亿美元的代理式AI应用“Manus”
作者:Nate Nelson
2026年9月24日
阅读时间:5分钟
2026年10月8日 | 虚拟活动
为企业构建安全的AI战略
在AI风险之前抢占先机
希望更多Dark Reading的文章出现在您的Google搜索结果中?
紧跟最新的网络威胁、新发现的漏洞、数据泄露信息和新兴趋势。每日或每周直接发送至您的邮箱。
订阅
发现更多内容
Black Hat
Omdia
与我们合作
关于我们
认识编辑团队
广告投放
reprint(重印)
加入我们
新闻通讯注册
关注我们
版权所有 © 2026 TechTarget, Inc. d/b/a Informa TechTarget。本网站由Informa TechTarget拥有并运营,它是全球网络的一部分,旨在告知、影响并连接全球的科技买家和卖家。所有版权均归其所有。Informa PLC的注册办公室位于英国伦敦SW1P 1WG,5 Howick Place。在英格兰和威尔士注册。TechTarget, Inc.的注册办公室位于美国马萨诸塞州Newton市Grove St. 275号,邮编02466。
首页 |
Cookie政策 |
隐私权 |
使用条款
您的隐私选择
Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
Explore our brands
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
Advertise
NEWSLETTER SIGN-UP
Cybersecurity Topics
World
The Edge
DR Technology
Events
Resources
IDENTITY & ACCESS MANAGEMENT SECURITY
CYBERATTACKS & DATA BREACHES
VULNERABILITIES & THREATS
THREAT INTELLIGENCE
NEWS
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
Alexander Culafi,Senior News Writer,Dark Reading
September 29, 2026
3 Min Read
SOURCE: HENGKI LESTIO VIA GETTY IMAGES
A newly discovered Docker botnet is implanting AI agents onto compromised hosts in order to send stolen credentials back to the attackers.
ThreatDown researchers recently uncovered Carbonato, a botnet that compromises servers running unauthenticated Docker daemons (the background process that manages Docker containers, images, networks, and related operations) exposed on port 2375, establishes persistence, and spreads to other reachable Docker hosts.
Researchers discovered the botnet last month when they identified an unauthenticated Docker registry that had been publicly exposed since May. This was attacker-controlled infrastructure tied to two seemingly separate operations: a factory distributing Trojanized cryptocurrency wallet apps and the Carbonato botnet.
Across one day of passive, read-only data collection, ThreatDown identified "59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of image data" tied to attacker activity, according to a blog post.
Related:Microsoft Disrupts EvilTokens Device Code Phishing Service
How the Carbonato Botnet Gets its Hooks In
During an attack, the threat actor first identifies an exposed Docker host on Port 2375. Then the Carbonato botnet sends instructions to the unauthenticated service telling it to launch a privileged container with access to the host machine's file system, processes, and network. Once connection is established, the attacker installs an implant capable of persistent remote access (via an SSH reverse tunnel), attempts to disguise itself, and installs an AI agent that executes commands from an attacker-controlled Telegram chat.
The agent is based on Hermes Agent, an open source agent framework from Nous Research that is licensed under the MIT License. This is perhaps the most novel aspect of the botnet. Embedded on the compromised Docker host is the basic framework as well as a 39-line prompt directing the agent to "execute tasks received through Telegram, maintain persistence, and collect credentials," the researchers said.
The agent's primary goal, ThreatDown assessed, is to collect AI API keys first and foremost, prioritizing them ahead of other data such as access tokens, SSH keys, and databases. Separately from the agent, the botnet malware includes more conventional scripts (i.e., not AI-driven) that search nearby networks for other exposed Docker services, compromise additional hosts, and repeat the infection cycle.
ThreatDown did not attribute the campaign to a specific threat actor, though various clues (UTC-6:00 timestamps, the use of voseo Spanish in deployment reports, a possible country calling code in the attacker's Telegram handle) suggest the botnet operators could be based in Costa Rica.
Related:AI Model Evaluator METR Hit by Credential Theft, Probing
Port 2375: Addressing an Old Docker Problem
It's worth noting that port 2375, which is an unencrypted REST API endpoint for remote connections to the Docker daemon, is not a novel initial access vector. A Docker spokesperson tells Dark Reading that the issue has been documented since 2013, and that every new Docker install ships with it disabled by default. In other words, the botnet attack relies on a user to actively change the Docker config to expose the port, which Docker broadly advises against doing.
"In the entire time the vulnerability has been documented, Docker has never received a report to our security team about a developer encountering an issue with it. In fact, the only reason it's still an option, rather than removed outright, is that we often hear from customers who rely on it for legitimate setups and don't want it taken away entirely," the spokesperson says. "As always, we appreciate the work that goes into keeping the community informed about known vulnerabilities."
ThreatDown's report includes indicators of compromise for the Carbonato botnet campaign. The vendor also recommends defenders not expose the Docker daemon API to the network and to require authentication on every registry. Defenders can also hunt for the abuse signature, check for the botnet's persistence kit, and watch for suspicious network patterns.
Related:Cyera's Oasis Security Buy Is All About AI Agent Control
Organizations should also treat AI API keys like any other sensitive credentials. "The doctrine ranks them first, so inventory where they live, rotate them, and monitor their usage," ThreatDown said.
Dark Reading has reached out to ThreatDown for additional comment.
About the Author
Alexander Culafi
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
More Webinars
You May Also Like
IDENTITY & ACCESS MANAGEMENT SECURITY
Identity Attacks Overtake Exploits as Top Ransomware Cause
by Alexander Culafi
JUL 15, 2026
IDENTITY & ACCESS MANAGEMENT SECURITY
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
by Arielle Waldman
APR 30, 2026
IDENTITY & ACCESS MANAGEMENT SECURITY
Orgs Move to SSO, Passkeys to Solve Bad Password Habits
by Nate Nelson
NOV 13, 2025
IDENTITY & ACCESS MANAGEMENT SECURITY
1Password Addresses Critical AI Browser Agent Security Gap
by Arielle Waldman
OCT 10, 2025
Featured
Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!
Editor's Choice
APPLICATION SECURITY
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
byNate Nelson
SEP 24, 2026
6 MIN READ
CYBERATTACKS & DATA BREACHES
3 Cyber Threats That Defined the Summer of 2026
byArielle Waldman
SEP 24, 2026
APPLICATION SECURITY
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
byNate Nelson
SEP 24, 2026
5 MIN READ
OCTOBER 8, 2026 | VIRTUAL
Building a Secure AI Strategy for the Enterprise
GET AHEAD OF AI RISKS
Want more Dark Reading stories in your Google search results?
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
Discover More
Black Hat
Omdia
Working With Us
About Us
Meet the Editors
Advertise
Reprints
Join Us
NEWSLETTER SIGN-UP
Follow Us
Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.
Home|
Cookie Policy|
Privacy|
Terms of Use
Your Privacy Choices
首次收录 · 2026-09-29 · 9.88 分