ShinyHunters seizes Cl0p leak site; Docker botnet targets AI keys

ShinyHunters says it copied server logs, source code and private keys from Cl0p’s Tor leak site. Researchers found a Docker botnet harvesting AI API keys and exposed water utility credentials.

ShinyHunters published a defacement of the Cl0p ransomware group’s Tor data leak site this week and claimed it copied server logs, source code and the private keys for Cl0p’s onion service. The group demanded an eight-figure payment and a public apology and tied the action to threats from a Cl0p representative linked to an Oracle E-Business Suite campaign.

Security researchers described a Docker-focused botnet called CARBONATO that compromises Docker daemons left exposed without authentication on port 2375. On infected hosts the operation installs an open-source AI agent framework named Hermes Agent, replaces the agent’s persona file so it follows operator commands delivered via Telegram, and ranks AI API keys as the highest-value target. The botnet scans adjacent networks about every five minutes to spread. Investigators located the operation after finding an exposed, unauthenticated Docker registry and reported language, timezone and infrastructure indicators consistent with operators in Costa Rica.

A separate analysis of stolen identity data tied to roughly 10,000 U.S. water and wastewater utilities and their technology suppliers found active infostealer logs at 1,787 organizations and credentials related to operational technology or remote-access systems at 258 entities. In one instance, malware on a single device at a metering-technology supplier captured saved logins for about 167 utility metering portals. Exposed credentials included accounts for remote-administration tools such as TeamViewer and management portals for SonicWall and Fortinet. The analysis stated these records represent potential access paths rather than confirmed intrusions.

Researchers also identified malicious packages posted to npm and PyPI that carry a Go implant named sckit. The implant activates when affected libraries are imported and searches for secrets across npm, PyPI, GitHub, AWS and model-hosting services. The code includes templates for spreading through package registries and automation workflows, though analysts have not observed widespread propagation to date.

Investigators found thousands of servers running open-source relay gateways that pool AI accounts so many users appear to come from the relay rather than from their real IP addresses. One U.S.-hosted cluster showed more than 4,000 IP addresses in China and Hong Kong routing to relays that reached major model providers.

Cl0p has used a Tor-based leak site to publish or sell data taken after ransomware attacks. ShinyHunters has previously published or sold breached datasets. Docker daemons exposed on the default management port have been exploited in prior campaigns because they permit remote control without authentication. Remote-administration credentials on utility networks can provide potential footholds into industrial systems.

Security vendors recommend securing exposed management interfaces, rotating and safeguarding API keys and service credentials, reviewing and auditing remote-access accounts, monitoring container registries and package indices for unusual uploads, and tightening controls on account sharing and relay services used with AI platforms.

Articles by this author