Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-26 · updated: 2026-09-26 · tags: [incident, global] · confidence: high · severity: low · affected_sectors: [global] · au_impact: true

ThreatDown found the Carbonato botnet in an unauthenticated Docker registry holding nearly 60 repositories and 4.3 GB of image data, with operational evidence spanning October 2024 to August 2026. It targets hosts whose Docker API is exposed on port 2375 without authentication: it connects to the API, instructs the daemon to launch a privileged container for host access, opens a reverse SSH tunnel, installs an SSH server with the operators' key, and reports the new deployment through Telegram. Persistence is layered across cron jobs, systemd timers, rc.local and OpenRC hooks, and worm-like scripts scan the host's attached networks every five minutes to find and infect further Docker daemons. The distinguishing feature is the payload: the operators install the Hermes Agent AI framework with an agent named "GH0ST" whose instructions overwrite the default SOUL.md persona file, and the model then interprets tasks received through Telegram, writes terminal commands, reads the output and decides the next step. ThreatDown could not attribute the activity to a known cluster and points to Costa Rica as a possible operator location; indicators include the CARBONATO_API_KEY setting and reverse SSH tunnels toward AS262145.

Attribute Detail
Sector Global (Macro)
Date 2026-09-26
Source BleepingComputer
Reliability Tier 2