CuraSec

Act active

Carbonato malware uses AI agents to hijack exposed Docker hosts

2026-09-25 15:49 UTC · BleepingComputer · read the source ↗ #docker#malware#botnet
  • Engineer — Act: If you expose Docker daemon sockets (TCP port 2375/2376) without auth, audit immediately and either bind to localhost-only or enforce TLS mutual auth; scan for Hermes Agent processes or unexpected AI framework containers on Docker hosts.
  • SOC/IR — Plan: Build detections for unexpected container spawns or Hermes Agent framework activity on Docker hosts; hunt for outbound C2 from container workloads as a new campaign variant to cover this quarter.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.