AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]
This article has been indexed from Security Affairs
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
