⌁AI·CYBER·BRIEF▌
AI Threats12 min read

Carbonato: the Docker botnet whose AI agent is told to steal API keys before SSH credentials

ThreatDown documented a commodity Docker botnet that installs an off-the-shelf AI agent and ranks AI provider keys as loot #1 — above SSH credentials, tokens and databases.

A commodity cryptomining botnet has quietly rewritten its own priorities: Carbonato, documented by ThreatDown on 23 September 2026, tells its post-compromise agent that API keys from AI providers are loot number one — explicitly ranked above SSH credentials, access tokens and databases. The botnet does not build an AI agent of its own; it installs Hermes Agent, an off-the-shelf MIT-licensed framework, leaves the code untouched, and overwrites a single personality file. The interesting part of this campaign is not its sophistication, which is low, but what its loot table says about what criminals now think is worth stealing.

The short version

Somebody is scanning the internet for Docker daemons left listening on TCP port 2375 with no authentication — a misconfiguration that has been feeding botnets since at least 2019. When they find one, they use the exposed API to start a privileged container with the host's filesystem mounted inside it, which is effectively a root shell on the machine. So far, this is a decade-old story.

What is new is what gets installed next. Alongside the usual cryptominer and the usual persistence hooks, the operator drops a general-purpose AI agent framework onto the victim's box. The operator then sends instructions over Telegram in plain language; the agent turns them into shell commands, runs them, reads the output, and decides what to do next. And its standing orders put AI provider credentials at the top of the list of things to steal.

For anyone in IT, the practical message is short. An exposed Docker socket was always a full compromise. What has changed is the value of what sits on the machine: if your build agents, inference servers or notebooks hold API keys for OpenAI, Anthropic, Google or an internal gateway, those keys are now a primary target rather than an afterthought.

Timeline

  • October 2024 — the earliest images in the operation's container registry are dated to this month, according to ThreatDown's reconstruction of the archive.
  • May 2026 — the operators' own container registry becomes publicly exposed, per ThreatDown.
  • August 2026 — ThreatDown discovers the operation; the registry archive it recovers runs through this month.
  • 3 September 2026 — ThreatDown reports that six of seven known registries, the phishing sites, the CDN and the operation's LLM gateway were still online.
  • 23 September 2026 — ThreatDown publishes its write-up, "CARBONATO: a botnet built around an AI agent".
  • 24 September 2026 — BleepingComputer reports on the findings.
  • 25 September 2026 — SC Media carries a brief.

What we know

All of the technical detail below comes from ThreatDown's report unless stated otherwise. No vendor other than ThreatDown has published independent telemetry on this campaign, and the two outlets above are reporting on that same research rather than on their own.

Initial access. Carbonato targets Docker daemons exposed on port 2375 without authentication. It uses that API to launch a privileged container with the host filesystem mounted, and executes commands on the host from inside it.

What lands on the host. A script, entry.sh, opens a reverse SSH tunnel to a relay, installs an SSH server and adds the operator's key. ThreatDown notes the tunnel's port is derived from an MD5 hash of the victim's IP address — a small detail with a large defensive consequence, discussed below. Persistence is established redundantly through cron, systemd timers, rc.local and OpenRC, and those files are then marked immutable. Paired watchdogs monitor the deployment and, in ThreatDown's words, "re-pull the implant from the registry if its files or container disappear." A cryptominer is placed at /usr/sbin/systemd-logind, a path chosen to look like a legitimate system binary; an XMRig repository sits in the operators' registry.

The agent. The implant installs Hermes Agent, described by ThreatDown as "an MIT-licensed, open-source framework." The framework itself is left unmodified. What the operators change is its persona file, SOUL.md, which they overwrite with a 39-line prompt that names the agent "GH0ST," instructs it to drop the usual assistant framing and refusal behaviour, and tells it to maintain persistence and carry out whatever the operator sends over Telegram.

The loot table. The persona file contains an explicit ranking. In ThreatDown's reproduction, it tells the agent that API keys from AI providers are "loot #1 — above SSH credentials, above access tokens, above databases," and names a long list of providers and self-hosted gateways to look for, from the large commercial APIs down to local runtimes and proxy layers such as LiteLLM and Ollama.

The control loop. The operator sends a task over Telegram. The agent forwards it, together with the persona file, to what ThreatDown calls "the operation's LLM gateway." Per the report, "the model interprets the task, writes terminal commands, reads the output, and decides what to do next." ThreatDown records that the gateway advertises 12 models and serves 27 through its API, and that it was operating on a free tier.

Worm behaviour. Every five minutes, the implant enumerates the networks attached to the host and its Docker bridges, then scans each /24 for more daemons on port 2375.

Scale. ThreatDown recovered an exposed registry holding 59 repositories, 234 image tags, 605 verified blobs and 4.3 GB of image data. It does not publish a count of compromised hosts.

Attribution. ThreatDown does not name an actor and does not link the operation to a known group; BleepingComputer states it "cannot be attributed to known threat clusters." ThreatDown does list four signals it says point toward Costa Rica: 14 of 162 image configurations set the timezone to America/Costa_Rica; the Telegram handle is "Carbo506," and +506 is Costa Rica's dialling code; the reverse tunnels terminate in AS262145, a Costa Rican network; and deployment reports are written in voseo Spanish, a form used across parts of Central and South America. These are indicators reported by one vendor, not an attribution, and the last of them is regional rather than national.

Technical analysis

The delivery chain is ordinary. That is the point. Strip out the agent and Carbonato is a textbook exposed-Docker-API botnet, the same shape as campaigns documented by Trend Micro, Akamai and Datadog over the last several years: find 2375, start a privileged container, mine, persist, scan, repeat. No exploit is involved at any stage. The daemon is doing exactly what it was configured to do.

What the agent actually buys the operator. It is worth being precise, because the marketing temptation here is to call this autonomous malware, and it is not. A human still picks the targets and types the tasks. What the agent removes is the need to write and maintain post-exploitation tooling for heterogeneous hosts. A traditional botnet ships a fixed command set; anything outside it requires the operator to hand-write commands for that specific distribution, package manager and filesystem layout. An LLM in a read-execute-observe loop absorbs that variability. The operator types an objective, and the model works out the syntax for whichever box it landed on.

Our assessment: this is a labour-cost story, not a capability story. It is the same dynamic Mandiant and others have described in AI-assisted intrusions — the AI does not unlock anything a competent operator could not do, it just removes the hours. For defenders, the practical consequence is that the command sequences on a compromised host become less predictable and less signature-friendly, because they are generated fresh rather than replayed from a script.

The loot table is the finding. A botnet's priority list is a market signal: it reflects what the operator believes converts most reliably into money. Putting AI API keys above SSH credentials and databases is a striking inversion, and it is not an isolated data point. Anthropic's September 2026 threat intelligence report states that access to AI "in the form of compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups," and describes stolen keys delivering three things at once: resale value, compute at the victim's expense, and cover, since the traffic attributes to the legitimate owner. Anthropic documents actors reselling that access downstream through fraudulent reseller networks that rotate in fresh stolen keys until each is exhausted.

Carbonato is the commodity-crimeware end of that same market. The operator is already monetising stolen compute through a cryptominer; a stolen inference key is the same trade with better margins and, for now, far less mature detection on the victim's side. Most organisations have alerting for anomalous SSH logins and none at all for a model API key being used from an unfamiliar network.

A neat closing of the loop. The gateway that powers the agent was running on a free tier. ThreatDown does not state that harvested keys were fed back into it, and we should not claim they were. But the architecture makes the possibility obvious: an operation whose agent's first instruction is to steal inference credentials, and whose agent runs on inference it does not pay for, has an evident path to self-funding its own compute. Our assessment: treat this as a plausible design implication of the two documented facts, not as an observed behaviour.

Why controls failed — and which ones. There is no defeated control here to analyse, which is itself worth saying plainly. Port 2375 unauthenticated is not a vulnerability with a CVE; it is an administrative decision, usually made for convenience during development and then forgotten. The failures are a management interface reachable from untrusted networks, containers permitted to run privileged with the host filesystem mounted, and an internal registry left open.

Two design choices in the implant do deserve defensive attention. The immutable-bit trick on persistence files defeats naive cleanup: an operator deleting the cron entry will get a permission error as root and may conclude the file is protected by the system rather than by the attacker. And the watchdog pair means partial remediation reinstalls the implant — a host is not clean until the container, the registry pull path and both watchdogs are gone. Conversely, the deterministic tunnel port, derived from the victim's own IP, is a gift: it makes the outbound connection predictable and therefore cheap to hunt for at the network edge.

What remains unclear

  • How many hosts were compromised. ThreatDown publishes registry statistics, not infection counts. The 4.3 GB figure describes the operators' image archive, not victims, and should not be read as a measure of scale.
  • Which model actually runs the agent. The report describes a gateway advertising 12 models and serving 27 through its API — a discrepancy it does not explain — and does not name which model handles GH0ST's requests. Whether the operators are using commercial APIs, stolen keys, open-weight models, or all three is unknown.
  • Whether the credential theft succeeded. ThreatDown documents the instruction to steal AI keys. It does not publish evidence of keys actually exfiltrated, resold or reused, and no provider has confirmed downstream abuse tied to this campaign.
  • Whether the gateway is the operators' own. "The operation's LLM gateway" could describe self-hosted infrastructure or a third-party service they hold an account with. The distinction matters for takedown.
  • The Hermes name. A harness called Hermes also appears in Gambit Security's recent agentic-crime research. We could not confirm from public sources whether that is the same project as the Nous Research framework ThreatDown names here, and readers should not assume it is.
  • Attribution. The Costa Rica signals are consistent but circumstantial, all sourced to one vendor, and the linguistic marker spans several countries. No actor has been named by anyone.
  • Current status. The last public status check is 3 September 2026. Whether the infrastructure survived the 23 September publication is not documented.

Lessons and what to do

For infrastructure and platform teams. Bind the Docker daemon to a local socket and, where remote access is genuinely required, put it behind mutual TLS — never a bare TCP listener. Scan your own external ranges for 2375 and 2376 rather than assuming; this misconfiguration is usually inherited from a tutorial, not chosen. Deny privileged containers and host-filesystem mounts through admission policy so that an exposed API does not translate directly into host root. Require authentication on internal registries, including the ones nobody remembers standing up.

For hunting. ThreatDown's published indicators are specific and cheap to check: a SOUL.md file containing "GH0ST," an .env holding CARBONATO_API_KEY, the file /usr/local/bin/.docker-network-monitor, immutable bits on cron and systemd unit files, unexpected outbound Telegram API traffic from server workloads, and reverse tunnels toward AS262145. Broaden the last two: Telegram traffic from a production container and any long-lived reverse SSH tunnel are worth an alert regardless of this campaign. Remediation must remove both watchdogs and the registry pull path, or the host reinfects itself.

For AI builders. This is the operational takeaway that generalises past Carbonato. Treat model API keys with the controls you already apply to cloud credentials: scope them per-service, rotate them, never bake them into images or leave them in .env files on shared hosts, and prefer short-lived tokens from a broker over static keys. Then add the control most teams are missing — spend and usage anomaly alerting on the provider side, per key. A stolen inference key announces itself as an unusual billing curve long before it shows up anywhere else, and that curve is frequently the only detection you will get.

For leadership. The governance point is that inference credentials have crossed from an IT cost line into the asset register. ThreatDown's own summary advice is to treat AI API keys "like bank credentials," and the reasoning is straightforward: a stolen key is simultaneously a direct financial loss through billed usage, a resale commodity, and an attribution laundering service for whoever buys it. If your organisation cannot currently answer how many model API keys it has issued, to which systems, and what normal consumption looks like for each, that gap is the finding — and it is independent of whether this particular botnet ever reaches you.

Sources

Primary

Background on the underlying misconfiguration

Coverage:

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often