Carbonato Botnet Compromises Docker Hosts to Deploy TelegramControlled Hermes AI Agent

Image for article Carbonato Botnet Compromises Docker Hosts to Deploy TelegramControlled Hermes AI Agent
News Source : Internet

News Summary

  • Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato.
  • At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to propagate further.
  • On each host, it installs Hermes Agent with instructions to follow operators' Telegram commands.
  • All of this is achieved by means of a shell script that launches a reverse SSH tunnel from the victim to a relay located in Costa Rica.
  • The activity has not been attributed to any known threat actor or group.

Must read Articles