C
月内に
認証なしで公開されているDocker API(ポート2375)を標的とする新しいボットネット「Carbonato」
📌 一言でいうと
認証なしで公開されているDocker API(ポート2375)を標的とする新しいボットネット「Carbonato」が発見されました。攻撃者は侵害したホストにAIエージェントフレームワークである「Hermes Agent」をインストールし、Telegram経由で制御されるGH0STエージェントを展開します。このボットネットの活動は2024年10月から確認されており、Dockerイメージのリポジトリを通じて配布されています。
🔍該当判定
- 社内でDocker(コンテナ仮想化ソフト)を利用している
- DockerのAPIポート(2375番)を外部(インターネット)に公開している
- Docker APIへのアクセスにパスワード認証や証明書認証を設定していない
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Docker API(特にポート2375)をインターネットに直接公開せず、認証を有効にするか、VPN/SSHトンネル経由でのアクセスに制限することを強く推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Docker APIの認証不備を突くボットネット「Carbonato」への対応について
お疲れさまです。Dockerホストを標的とした新しいボットネットに関する情報共有です。
■ 概要
認証なしで公開されているDocker API(ポート2375)を悪用し、AIエージェントフレームワーク(Hermes Agent)およびGH0STエージェントをインストールして遠隔操作を行うボットネット「Carbonato」が観測されています。
■ 影響範囲
- ポート2375で認証なしにAPIを公開しているDockerホスト
■ 対応手順
1. 外部からポート2375へのアクセスが許可されていないか、ファイアウォール設定を確認してください。
2. Docker APIを外部に公開する必要がある場合は、必ずTLS認証を導入してください。
3. 不審なDockerイメージのプル履歴や、Hermes Agent等の未知のプロセスが動作していないか確認してください。
■ 参考情報
- ThreatDown Analysis
対応優先度: 高
対応期限: 直ちに確認
お疲れさまです。Dockerホストを標的とした新しいボットネットに関する情報共有です。
■ 概要
認証なしで公開されているDocker API(ポート2375)を悪用し、AIエージェントフレームワーク(Hermes Agent)およびGH0STエージェントをインストールして遠隔操作を行うボットネット「Carbonato」が観測されています。
■ 影響範囲
- ポート2375で認証なしにAPIを公開しているDockerホスト
■ 対応手順
1. 外部からポート2375へのアクセスが許可されていないか、ファイアウォール設定を確認してください。
2. Docker APIを外部に公開する必要がある場合は、必ずTLS認証を導入してください。
3. 不審なDockerイメージのプル履歴や、Hermes Agent等の未知のプロセスが動作していないか確認してください。
■ 参考情報
- ThreatDown Analysis
対応優先度: 高
対応期限: 直ちに確認
Subject: [Security Alert] Botnet 'Carbonato' Targeting Unauthenticated Docker APIs
Dear IT/Security Team,
We are sharing information regarding a new botnet named 'Carbonato' that targets insecure Docker configurations.
■ Overview
Carbonato exploits Docker hosts where the API is exposed without authentication on port 2375. It installs the 'Hermes Agent' AI framework and deploys a GH0ST agent, allowing operators to control the system via Telegram.
■ Scope
- Docker hosts with API port 2375 exposed to the internet without authentication.
■ Mitigation Steps
1. Verify firewall rules to ensure port 2375 is not exposed to the public internet.
2. Implement TLS authentication for any required remote Docker API access.
3. Audit running processes and Docker image pull history for signs of 'Hermes Agent' or unauthorized GH0ST agents.
■ Reference
- ThreatDown Analysis
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a new botnet named 'Carbonato' that targets insecure Docker configurations.
■ Overview
Carbonato exploits Docker hosts where the API is exposed without authentication on port 2375. It installs the 'Hermes Agent' AI framework and deploys a GH0ST agent, allowing operators to control the system via Telegram.
■ Scope
- Docker hosts with API port 2375 exposed to the internet without authentication.
■ Mitigation Steps
1. Verify firewall rules to ensure port 2375 is not exposed to the public internet.
2. Implement TLS authentication for any required remote Docker API access.
3. Audit running processes and Docker image pull history for signs of 'Hermes Agent' or unauthorized GH0ST agents.
■ Reference
- ThreatDown Analysis
Priority: High
Deadline: Immediate