$ techbeacon▋
DDoS

CARBONATO Botnet Hijacks Docker Hosts by Repurposing Open‑Source Hermes Agent

CARBONATO Botnet Hijacks Docker Hosts by Repurposing Open‑Source Hermes Agent

Security researchers have uncovered a new malicious campaign, dubbed CARBONATO, that turns the legitimate Hermes Agent framework into a covert command‑and‑control layer for compromised Docker servers.

Hermes Agent is an open‑source tool designed to help developers manage container workloads through a programmable interface. Its flexibility and ease of integration have made it popular in cloud‑native environments, but CARBONATO operators have re‑engineered the code to act as an interactive post‑compromise shell, allowing attackers to issue commands on any infected host.

The infection chain begins with automated scanners that probe the internet for Docker daemons listening on the default TCP port 2375 without any form of authentication. Once an exposed daemon is located, the malware leverages the Docker API to pull a malicious image, launch a container, and install the modified Hermes Agent inside it. The agent then opens a back‑channel that lets the attackers control the host as if they were logged in locally.

What sets CARBONATO apart from earlier Docker‑focused malware is its worm‑like behavior. After establishing a foothold, the compromised container scans the internal network for additional Docker endpoints, repeats the same exploit routine, and propagates the agent laterally. This self‑replicating mechanism enables the botnet to rapidly expand across clustered environments, data‑center segments, or any network segment where Docker APIs are left unprotected.

The emergence of CARBONATO highlights a growing risk vector for organizations that rely on containerization but have not hardened their Docker deployments. Exposing the Docker daemon without TLS or proper firewall rules effectively grants anyone on the network—or the wider internet—full root‑level access to the host. Because containers share the host kernel, a breach can quickly lead to full system compromise, data exfiltration, or the use of the infrastructure for cryptocurrency mining and other illicit activities.

Cyber‑security firms monitoring the threat have begun sharing indicators of compromise, including the specific Docker image tags and the altered Hermes Agent binary. Experts recommend that administrators disable the unauthenticated TCP socket, enforce mutual TLS authentication for API access, and restrict network exposure through host‑based firewalls or cloud security groups. Regular audits of running containers and the removal of unnecessary images can also reduce the attack surface.

As CARBONATO continues to evolve, researchers warn that other open‑source projects could be similarly co‑opted for malicious purposes. The incident underscores the importance of maintaining strict supply‑chain hygiene and promptly applying security patches to both container runtimes and the tools that interact with them.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related