New Carbonato malware uses AI agents to hijack exposed Docker hosts
5 Articles
5 Articles
Carbonato targets exposed Docker daemons
Carbonato is a botnet malware targeting Docker APIs exposed on port 2375 without authentication. It deploys a privileged container, opens reverse SSH access, installs the Hermes Agent framework with a GH0ST persona, reports via Telegram, and...
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO… Read more →
CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs
1. Basic Information Original Title: CARBONATO: a botnet built around an AI agent Source: ThreatDown Published Date: 2026-09-22 Updated Date: None Collection Date: 2026-09-25T08:28:50+09:00 Report Type: Threat Intelligence Severity: Critical Basis of Severity: ThreatDown analyzed recovered containers and scripts, identifying host intrusion, persistence, propagation, mining, and AI agent-driven operational capabilities. Although the exact number …
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium







