BlackTree Security · Infrastructure · Automation · AI

An Open Docker Port Gave Attackers Their Own AI Operator

ThreatDown’s Carbonato investigation describes attackers taking over hosts through Docker APIs exposed without authentication. The campaign then installs an AI agent to help the operator work on the compromised machine. The entry point is administrative exposure, not a newly discovered Docker or agent-framework vulnerability.

The daemon supplies the authority

Researchers observed privileged containers with host access, SSH persistence and repeated scanning of connected networks. Carbonato installs the stock Hermes Agent framework with a hostile persona called GH0ST, receiving human-directed tasks through Telegram. Its instructions prioritise AI API keys and other credentials.

ThreatDown reconstructed the campaign from exposed attacker infrastructure. Its report does not establish a comprehensive victim count or prove that every exposed Docker listener has been compromised.

AI changes the work after entry

The operational concern is the combination of control and adaptability. Once an attacker can command a host, an agent can help interpret unfamiliar tools and results. That does not remove the human operator or make the initial access autonomous.

Defenders should separate prevention from investigation. Closing an exposed listener is a preventive control. If it was already abused, rebuilding a container alone may leave host changes and stolen credentials outside the response. Establish what the daemon could mount, which networks it could reach and which secrets were available before deciding the scope.

What Docker and cloud teams should do

  • Remove unauthenticated Docker APIs from the network. Do not expose port 2375 to the internet or broad internal segments. Use authenticated, encrypted administrative paths where remote control is genuinely required.
  • Inventory daemon listeners. Check cloud security groups, host firewalls, load balancers, development tunnels and forgotten test systems.
  • Hunt beyond the container list. Review privileged container creation, host filesystem mounts, namespace access, new SSH keys, reverse tunnels and persistence in cron, systemd, OpenRC and shell configuration.
  • Use the original investigation for indicators. Compare current findings with ThreatDown’s technical report, then validate matches against local evidence.
  • Rotate secrets based on evidence. AI provider keys, SSH credentials, repository tokens, cloud credentials and database secrets present on a compromised host may all need investigation and rotation.
  • Check adjacent networks. Because the implant scans attached networks repeatedly, containment should include bridge and overlay networks reachable from the affected host.

BlackTree has previously covered a container-to-host boundary failure and criminal use of agent frameworks against retailers. Carbonato combines those concerns without needing a Docker zero-day: an exposed daemon supplies the authority, and an off-the-shelf agent supplies the operator interface.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *