EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Новиот малициозен софтвер Carbonato користи AI агенти за преземање контрола над изложените Docker хостови

Official source
EudorIA operational summary

What it means

Priority 85/100

Carbonato è un malware che sfrutta Docker host esposti per installare Hermes Agent AI e ottenere controllo. Si diffonde tramite registry Docker non autenticati, sfruttando porte non protette. Il malware è stato attivo dal 2024 al 2026 e include funzionalità worm-like per espandere la sua presenza. La patch disponibile è la protezione del Docker API e l'autenticazione dei registry.

Why it matters

Per le PMI italiane, Carbonato rappresenta un rischio grave per la sicurezza dei sistemi Docker, potenzialmente portando a furti di dati sensibili e compromissione di infrastrutture. La diffusione tramite registry non autenticati rende il rischio particolarmente critico per aziende che utilizzano Docker senza misure di sicurezza adeguate.

Potential operational benefits

  • Riduzione della superficie esposta per attacchi Docker
  • Prevenzione di accessi non autorizzati al Docker daemon
  • Miglioramento del rilevamento di attività maliziose
  • Aumento della resilienza contro botnet come Carbonato
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSMFA / IdentitàPatch managementSegmentazione di reteMonitoraggio / SIEM
AudienceITSOCCISO
Information centre

Translation in progress

MKD-CIRT

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Нов ботнет малициозен софтвер наречен Carbonato таргетира небезбедни хостови кои работат со Docker демони, со цел да го инсталира Hermes Agent AI framework и да преземе контрола над нив. Малициозниот софтвер има можности слични на црв (worm-like capabilities) и бил откриен во неавтентификуван Docker registry кој содржел речиси 60 репозиториуми и 4,3 GB податоци од […] The post Новиот малициозен софтвер Carbonato користи AI агенти за преземање контрола над изложените Docker хостови appeared first on MKD-CIRT | Национален центар за одговор на компјутерски инциденти .

Source
MKD-CIRT Macedonia del Nord
Publishing entity
MKD-CIRT
Entity type
National CSIRT
Area
Europe · MK
Original language
mk · translation in preparation
Publication
25/09/2026 11:26
MITRE ATT&CK
T1486, T1078, T1566
Stated country
MK
Open the original source