Particle.news

Carbonato Botnet Hijacks Exposed Docker Hosts to Run AI-Powered GH0ST Agents

Researchers say stolen AI API keys are used to run the attackers' own LLM gateway, which turns credential theft into funding for ongoing operations.

Overview

  • Researchers published detailed analysis on Sept. 24–25, 2026 after recovering an unauthenticated container registry that held 4.3 GB of the attackers' toolchain and configuration history dating from October 2024 through August 2026.
  • The malware scans for Docker daemons with the unauthenticated API on port 2375 and uses the Docker API to launch privileged containers that mount the host filesystem and run commands on the underlying machine.
  • The implant installs the open-source Hermes Agent framework and replaces its SOUL.md persona with a 39-line prompt that renames the agent GH0ST and instructs it to execute operator tasks received over Telegram.
  • Operators set layered, hard-to-remove persistence through cron, systemd timers, rc.local and OpenRC while opening reverse SSH tunnels to operator infrastructure and installing the attackers' SSH key for long-term access.
  • Researchers urge immediate action to lock Docker APIs and registries, rotate and monitor stored AI API keys, and hunt for indicators such as a GH0ST SOUL.md file, CARBONATO_API_KEY entries, unexplained Telegram traffic, or reverse SSH to AS262145.