Carbonato Botnet Compromises Docker Hosts to Deploy TelegramControlled Hermes AI Agent
News Source : Internet
News Summary
- Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato.
- At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to propagate further.
- On each host, it installs Hermes Agent with instructions to follow operators' Telegram commands.
- All of this is achieved by means of a shell script that launches a reverse SSH tunnel from the victim to a relay located in Costa Rica.
- The activity has not been attributed to any known threat actor or group.
Never miss a story from us, subscribe to our newsletter