New Carbonato malware uses AI agents to hijack exposed Docker hosts
9 Articles
9 Articles
Carbonato targets exposed Docker daemons
Carbonato is a botnet malware targeting Docker APIs exposed on port 2375 without authentication. It deploys a privileged container, opens reverse SSH access, installs the Hermes Agent framework with a GH0ST persona, reports via Telegram, and...
CARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent — and It Has Been Running Since October 2024
CARBONATO is a Docker-based botnet that utilizes an autonomous AI agent as its command-and-control (C2) engine rather than a static server. Discovered by ThreatDown researchers in August 2026, this is the first documented instance where the C2 infrastructure reasons through its environment to adapt to the specific configuration of each compromised host, moving beyond the […]
After the first access, a legitimate AI tool with a new role comes into play.
The botnet CARBONATO hijacks Docker servers with port 2375 open and uses stolen API keys to pay for its own AI gateway. La entrada Botnet CARBONATO IA: hijack Docker servers and pay for your LLM gateway aparece primero en Moncloa.
Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
CARBONATO is a botnet that turns Docker servers into footholds for attackers. It places an AI agent inside compromised systems, letting operators send tasks through Telegram and receive results. The campaign begins with Docker services carelessly exposed to the internet without authentication. Once inside, CARBONATO launches a privileged container, gains access to the host, establishes […]
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium











