Cybersecuritynews iconCybersecuritynewsSep 25, 2026 ~6 min source read

CARBONATO: A Botnet That Installs an AI Agent Inside Exposed Docker Hosts

Researchers found a botnet that targets unauthenticated Docker services, installs a language-model–driven agent, and uses Telegram and a model gateway to receive operator tasks and exfiltrate secrets.

Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers

Share this story

Send the public story page.

Useful takeaways from this story.

CARBONATO exploits Docker daemons exposed without authentication to run privileged containers that gain host access and persistent footholds.

The attackers install an unmodified open-source Hermes Agent, replacing only its persona instructions so it collects secrets and follows Telegram-delivered commands processed through an LLM gateway.

The useful part

It places an AI agent inside compromised systems, letting operators send tasks through Telegram and receive results. The campaign begins with Docker services carelessly exposed to the internet without authentication. Once inside, CARBONATO launches a privileged container, gains access to the host, establishes reboot persistence, and searches nearby networks for vulnerable servers.

How it works

  • ThreatDown researchers identified the operation after finding an unauthenticated Docker registry exposed since May 2026.
  • In one day, they recovered 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of data spanning October 2024 through August 2026.
  • ThreatDown said in a report shared with Cyber Security News (CSN) that the finding shows how one simple configuration mistake can become a network-wide problem.
  • Researchers Found a Botnet That Uses an AI Agent CARBONATO installs the open-source Hermes Agent framework without changing its software.
  • entry.sh​ ​v5.3,​ ​tier​ ​1 (Source – Threatdown) Sensitive AI API keys top the agent's list of targets, ahead of SSH credentials, access tokens, and databases.

What to take from it

This distinction matters because blocking every installation of a legitimate agent would also disrupt ordinary users. CARBONATO creates persistence through cron jobs, systemd timers, startup scripts, and OpenRC, then makes related files difficult to change. Its exposed image layers and configurations gave researchers a detailed view of the operation, underscoring the wider security risks of private container image exposure when registries lack proper access controls.

Example or evidence

  • Researchers also found that the gateway advertised 12 models but served 27 through its interface.
  • Infected hosts could therefore become sources of AI credentials as well as more conventional secrets, a concern also seen in malware targeting developer credentials across build environments.
  • ThreatDown cited language, build timestamps, a Telegram handle, and reverse tunnels as clues pointing toward Costa Rica.
  • Instead, the attackers replace its persona file with 39 lines of instructions that tell it to maintain access, collect secrets, and obey commands arriving through Telegram.

Details worth keeping

An operator's task travels with those instructions to the group's language model gateway. The model interprets the request, writes terminal commands, checks their output, and decides what to try next. The agent runs those commands on the victim server and reports back through Telegram.

Related coverage

  • Smartermsp: Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain...
  • Wired: Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
  • Gbhackers: An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation.
  • Infosecurity Magazine: Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
  • Cybersecuritynews: A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print...

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app