Skip to content
New Carbonato malware uses AI agents to hijack exposed Docker hosts

New Carbonato malware uses AI agents to hijack exposed Docker hosts

Ground.News • September 25, 2026

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Carbonato targets exposed Docker daemons

Carbonato is a botnet malware targeting Docker APIs exposed on port 2375 without authentication. It deploys a privileged container, opens reverse SSH access, installs the Hermes Agent framework with a GH0ST persona, reports via Telegram, and...

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

1. Basic Information Original Title: CARBONATO: a botnet built around an AI agent Source: ThreatDown Published Date: 2026-09-22 Updated Date: None Collection Date: 2026-09-25T08:28:50+09:00 Report Type: Threat Intelligence Severity: Critical Basis of Severity: ThreatDown analyzed recovered containers and scripts, identifying host intrusion, persistence, propagation, mining, and AI agent-driven operational capabilities. Although the exact number …

50 % of the sources are Center , 50 % of the sources lean Right

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage