Skip to content
New CARBONATO Botnet Targets Exposed Docker Daemons Using AI

New CARBONATO Botnet Targets Exposed Docker Daemons Using AI

First seen 24 Sep 2026, 22:56 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 23:58 UTC
  • •CARBONATO exploits unauthenticated Docker daemons on port 2375.
  • •The botnet uses the Hermes Agent AI framework for command execution and data collection.
  • •Researchers recommend securing Docker APIs to prevent infections.

ThreatDown researchers have identified a new botnet malware named CARBONATO that exploits insecure Docker daemons to install the Hermes Agent AI framework. The malware was discovered in an unauthenticated Docker registry containing 59 repositories and 4.3 GB of image data. CARBONATO spreads across Docker hosts with APIs exposed on port 2375, allowing it to launch privileged containers and establish persistence. The botnet collects sensitive data such as API keys and SSH credentials, reporting back to operators via Telegram. The operational evidence spans from October 2024 to August 2026, linking CARBONATO to a campaign distributing counterfeit cryptocurrency wallet apps. Researchers have not attributed the botnet to any known threat clusters but suspect Costa Rica as a possible location for the operators. Recommendations to prevent infection include disabling unauthenticated Docker APIs and securing registries.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-10-01
Operational evidence collection began
ThreatDown started collecting evidence of CARBONATO's operations, documenting activities from October 2024.
ThreatDown
2026-08-01
Discovery of unauthenticated Docker registry
ThreatDown researchers found an unauthenticated Docker registry that had been publicly exposed since May 2026.
ThreatDown
2026-09-24
CARBONATO malware reported
BleepingComputer reported on the new CARBONATO malware targeting Docker hosts, detailing its capabilities and impact.
BleepingComputer

More articles in this cluster (2)

Following this threat?

Track Carbonato in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed