The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The Carbonato botnet malware campaign, active from October 2024 to August 2026, targeted exposed Docker daemon APIs on port 2375 to deploy AI-powered attack frameworks. Attackers used the malware to install the Hermes Agent AI framework with a custom 'GH0ST' persona, enabling autonomous command execution, credential theft, and lateral movement across containerized environments. The operation utilized Telegram for command and control while establishing persistent backdoors through SSH tunnels and system service modifications across compromised Docker hosts.

This incident highlights the emerging threat of AI-augmented malware that can autonomously adapt attack strategies and execute complex multi-stage operations without constant human oversight, representing a significant evolution in automated cyber threats.

Why This Matters Now

AI-powered malware like Carbonato represents a paradigm shift where autonomous agents can execute sophisticated attacks, adapt tactics in real-time, and operate with minimal human intervention, dramatically increasing the scale and speed of cyber operations targeting cloud infrastructure.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Carbonato exploits exposed Docker daemon APIs on port 2375 without authentication, launching privileged containers to gain host access and establish persistence through SSH tunnels and system service modifications.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain the Carbonato malware's lateral spread and reduce blast radius through workload segmentation and east-west traffic controls. The framework's identity-aware routing and controlled egress policies could limit the scope of compromise across exposed Docker environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Container workload segmentation policies would likely limit the privileged container's ability to access host resources and restrict lateral communication pathways from the compromised Docker daemon

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Host-level segmentation policies would likely restrict the compromised container's ability to establish unauthorized SSH services and limit system-level persistence mechanisms to isolated network segments

Lateral Movement

Control: East-West Traffic Security

Mitigation: Network segmentation controls would likely constrain the malware's ability to scan across network boundaries and reduce reachability to additional Docker daemon endpoints during lateral propagation attempts

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Cross-cloud traffic monitoring and control policies would likely detect and constrain unauthorized C2 communications, reducing the AI agent's ability to maintain persistent command channels across cloud environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely restrict the AI agent's ability to exfiltrate sensitive credentials and constrain data transmission pathways to unauthorized external Telegram endpoints

Impact (Mitigations)

Residual botnet operations would likely be constrained to isolated network segments with limited access to additional infrastructure, reducing the overall scope of cryptocurrency mining and exploitation capabilities

Impact at a Glance

Affected Business Functions

  • Container Orchestration
  • Cloud Infrastructure Management
  • Development and Deployment Pipelines
  • Data Processing Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $250,000

Data Exposure

Compromise of SSH credentials, API keys, access tokens, and potential exposure of containerized application data. AI agent framework enables automated credential theft and lateral movement across Docker infrastructure.

Recommended Actions

  • • Implement Zero Trust segmentation to prevent unauthorized access to Docker daemon APIs and enforce identity-based policies for container orchestration platforms
  • • Deploy egress security controls to block unauthorized Telegram traffic and prevent AI agent C2 communications to external command servers
  • • Enable multicloud visibility and anomaly detection to identify suspicious automation patterns, repeated API calls, and unauthorized container deployments
  • • Strengthen Kubernetes security with namespace enforcement and pod-to-pod segmentation to contain container breakout attempts
  • • Deploy inline threat detection to identify and block malicious payload delivery and exploit traffic targeting container infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image