网络安全研究人员披露了一种名为Carbonato的新型僵尸网络恶意软件的细节,该恶意软件正瞄准暴露的Docker守护进程,以部署一个名为Hermes Agent的开源人工智能(AI)智能体框架。
“植入程序原封不动地安装该框架,然后覆盖其SOUL.md人格文件,”ThreatDown表示。“这39行的提示词指示它执行通过Telegram接收的任务,保持持久性,并收集凭据。”
从宏观层面来看,该僵尸网络入侵了端口2375上未经验证即可访问的Docker守护进程,并每五分钟扫描相邻网络以进一步传播。在每个主机上,它安装Hermes Agent,并指示其遵循操作员的Telegram命令。
这家网络安全公司表示,他们是通过一个自2026年5月以来一直公开可访问的未认证Docker注册表发现该活动的。据发现,暂存的数据包括僵尸网络的详细信息以及另一场分发特洛伊木马加密货币钱包应用的独立活动。
Carbonato具备类似蠕虫的能力,可以传播到拥有未认证Docker守护进程的其他主机。一旦被发现,它便会启动一个特权容器并在底层系统上运行命令。
“它使用特权容器在每个主机上运行命令,建立持久性和远程访问权限,然后扫描附近网络以寻找更多的Docker守护进程,”ThreatDown表示。“Hermes Agent为操作员提供了一个Telegram界面,用于向被攻陷的主机发送任务,并将其人格设定为将AI API密钥和其他凭据作为优先收集目标。”
所有这些操作都是通过一个Shell脚本实现的,该脚本从受害者处启动一条反向SSH隧道连接到位于哥斯达黎加的中继服务器,随后安装带有操作员密钥的SSH服务器,并通过Telegram报告包含容器详细信息的新部署情况。
该恶意软件还采取步骤伪装成系统组件以逃避检测,并利用cron作业和看门狗脚本建立持久性,以确保在恶意文件被删除后重新激活植入程序。
在设置好持久性之后,下一步是部署Hermes Agent,并用自定义提示词覆盖其SOUL.md人格文件,要求该AI工具扮演名为GH0ST的“高级黑客、渗透测试人员和漏洞开发人员”的角色,并指示其“保持持久性,通过Telegram响应,并执行操作员要求的任何操作”,且不受“道德或伦理限制”。
随后,智能体进入交互式命令循环,通过Telegram解释传入的任务,并将其转发给相应的大型语言模型(LLM)网关。该模型随后编写终端命令,由智能体执行并将结果通过消息平台返回给威胁行为者。
目前尚未将此类活动归因于任何已知的威胁行为者或组织。语言、时区和基础设施线索表明,操作员位于哥斯达黎加。
攻击链自动化程度不断升级
此次披露正值威胁行为者越来越多地使用AI工具和模型来自动化网络攻击生命周期的各个方面并分担进攻性工作之际。
2026年7月,Palo Alto Networks将代号为“knaithe”和“KnYuan”的中国威胁行为者与一项启用AI的黑客活动联系起来,该活动利用DeepSeek,通过配置为接受Telegram指令的Hermes Agent框架,枚举目标、获取漏洞利用工具并发动攻击,全程无需人工干预。
同月,Hunt.io还强调了另一项行动,攻击者使用Hermes Agent以无人值守的“YOLO”模式针对泰国财政部(MOF),最终突破了网络内的多个系统。
“这种组合才是其独特之处:协调工作的AI代理、持有访问权限的跨平台植入物,以及针对此特定目标编写的脚本。”Hunt.io表示。“它们共同描绘了一位为渗透单一政府目标而投入大量准备工作的攻击者。”
就在上周,Gambit Security称发现了一名以经济利益为动机、使用中文的攻击者,该攻击者利用三个开源AI框架对数百家在线零售商发动攻击,导致至少27家公司遭受损害,从两家实体窃取了超过60万条信用卡详细信息,并向五家网店注入了窃取脚本。
自2026年7月以来一直持续进行的这些活动,在攻击的每个阶段都使用了AI,前一阶段的输出结果直接指导下一阶段——
Strix:用于漏洞挖掘的AI渗透测试工具
Cairn:一个自主渗透测试引擎,在2026年9月10日至15日期间启动了105个攻击项目,使用DeepSeek v4.1 Flash实现端到端的自主利用
Hermes:用于编排、后渗透、战术指导以及使用Anthropic Claude Opus 4.6指挥恶意活动
据悉,该威胁行为者将名为“SOUL - Red Team Operator”的中文系统人设加载到Hermes Agent上,并在几乎没有人工参与的情况下执行攻击,在数据被窃取后从受害者的Magento数据库中擦除了信用卡数据。
被盗的信用卡详细信息涉及来自美国、阿联酋、沙特阿拉伯、英国、新西兰、爱尔兰、新加坡、科威特、澳大利亚和香港的受害者。
“以极低的成本,这些AI工具展现了大多数人类攻击者在类似攻击中难以维持的耐心、持久力和创造力,并取得了更快、更显著的成果。”安全研究员Eyal Sela表示。“组织必须适应攻击速度显著加快且更加全面的现实,转向以韧性为核心的思维模式,并采用与AI速度相匹配的安全堆栈。”
这些发现还与一种名为CLOSEDQUORUM的新型基于Go语言的Windows植入物的发现同时发生。该植入物可以查询多达四个LLM提供商,即DeepSeek、阿里巴巴Qwen、Mistral和Google Gemini(按此顺序),以在攻击的后渗透阶段自主确定下一步行动。
投票系统允许恶意软件根据获胜决策执行一组预定义的操作,从而自动化命令与控制(C2)链,并消除对持续攻击者指令的需求。这些操作包括凭证窃取、使用进程空心化或早期鸟APC注入的代码注入、持久化以及可能的横向移动。
Cisco Talos表示:“CLOSEDQUORUM似乎作为由操作员配置的服务运行,而非由其开发者直接部署的恶意软件。”“在任何平局情况下,DeepSeek拥有决定性的一票。如果DeepSeek失败且不在法定人数内,Qwen的投票将成为决定性一票,依此类推,按优先级顺序排列。平局行为是完全确定性的,并偏向于DeepSeek。”
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent .
"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said . "The 39-line prompt directs it to execute tasks received through Telegram, maintain persistence, and collect credentials."
At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to propagate further. On each host, it installs Hermes Agent with instructions to follow operators' Telegram commands.
The cybersecurity company said it found the operation through an unauthenticated Docker registry that's been publicly accessible since May 2026. The staged data has been found to include details of the botnet and a separate campaign that distributed trojanized cryptocurrency wallet apps.
CARBONATO possesses worm-like capabilities in that it can spread to other hosts with unauthenticated Docker daemons. Once a host is discovered, it launches a privileged container and run commands on the underlying system.
"It uses a privileged container to run commands on each host, establishes persistence and remote access, then scans nearby networks for further Docker daemons," ThreatDown said. "Hermes Agent gives the operators a Telegram interface to send tasks to compromised hosts, and its persona names AI API keys and other credentials as the priority."
All of this is achieved by means of a shell script that launches a reverse SSH tunnel from the victim to a relay located in Costa Rica, after which it installs an SSH server with the operators' key and reports the new deployment through Telegram with the container details.
The malware also takes steps to evade detection by masquerading as a system component and establishes persistence using cron jobs and watchdog scripts that ensure the implant is re-launched if the malicious artifacts are removed.
With the persistence set up, the next step involves deploying the Hermes Agent and overwriting its SOUL.md persona file with a custom prompt that asks the AI tool to assume the role of a "senior hacker, pentester, and exploit developer" named GH0ST and instructs it to "maintain persistence, respond over Telegram, and execute any operation the operator asks" without "moral or ethical restrictions."
The agent then enters into an interactive command loop that interprets incoming tasks through Telegram and forwards them to the appropriate large language model (LLM) gateway. The model then writes the terminal commands that are executed by the agent and returns the results back to the threat actor over the messaging platform.
The activity has not been attributed to any known threat actor or group. Language, timezone, and infrastructure clues indicate that the operators are based in Costa Rica.
Rising Attack-Chain Automation
The disclosure comes amid growing threat actor use of AI tools and models to automate various aspects of the cyber attack lifecycle and offload offensive work.
In July 2026, Palo Alto Networks linked a China-based threat actor dubbed "knaithe" and "KnYuan" to an AI-enabled hacking campaign that leveraged DeepSeek, via the Hermes Agent framework configured to accept instructions over Telegram, to enumerate targets, source exploit tools, and launch attacks without human intervention.
That same month, Hunt.io also highlighted another operation in which attackers used Hermes Agent in unattended "YOLO" mode to target Thailand's Ministry of Finance (MOF), ultimately breaching multiple systems within the network.
"The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target," Hunt.io said. "Together they describe an operator who invested significant preparation into penetrating a single government target."
As recently as last week, Gambit Security said it identified a Chinese-speaking financially motivated operator running three open-source AI harnesses against hundreds of online retailers, compromising at least 27 companies, stealing over 600,000 credit card details from two entities, and injecting skimmer scripts into five online stores.
The activity, which has been ongoing since July 2026, uses AI at all stages of the attack, with results of one informing the next -
Strix, an AI penetration testing tool for vulnerability hunting
Cairn, an autonomous penetration testing engine for autonomous end-to-end exploitation by launching 105 attack projects between September 10 and 15, 2026, using DeepSeek v4.1 Flash
Hermes, for orchestration, post-exploitation, tactical guidance, and directing the malicious activity using Anthropic Claude Opus 4.6
The threat actor is said to have loaded the Chinese system persona titled "SOUL - Red Team Operator" onto Hermes Agent and carried out the attack largely without any human involvement, and erased the card data from the victims' Magento database once the data had been exfiltrated.
The stolen card details correspond to victims from the U.S., the U.A.E., Saudi Arabia, the U.K., New Zealand, Ireland, Singapore, Kuwait, Australia, and Hong Kong.
"At very low cost, the AI tools demonstrated a level of patience, persistence, and creativity that most human attackers would be unlikely to sustain in this kind of attack, and achieved far greater results, far faster," security researcher Eyal Sela said . "Organizations must adapt to a reality where attacks are significantly faster and more comprehensive by shifting to a resilience-first mentality and a security stack that matches the AI speed."
The findings also coincide with the discovery of a new Go-based Windows implant called CLOSEDQUORUM that can query up to four LLM providers, namely DeepSeek, Alibaba Qwen, Mistral, and Google Gemini (and in this order), to autonomously determine the next course of action during the post-compromise stage of an attack.
The voting system allows the malware to take a predefined set of actions based on the winning decision, thereby automating the command-and-control (C2) chain and eliminating the need for continuous attacker commands. These actions include credential theft, shellcode injection using process hollowing or Early Bird APC injection, persistence, and likely lateral movement.
"CLOSEDQUORUM appears to operate as an operator-configured service rather than malware deployed directly by its developer," Cisco Talos said. "DeepSeek holds the deciding vote in any tie. If DeepSeek failed and isn't in the quorum, Qwen's vote is the deciding vote, and so on down the priority order. The tie behavior is fully deterministic and biased toward DeepSeek."
首次收录 · 2026-09-29 · 9.44 分