The useful part
It places an AI agent inside compromised systems, letting operators send tasks through Telegram and receive results. The campaign begins with Docker services carelessly exposed to the internet without authentication. Once inside, CARBONATO launches a privileged container, gains access to the host, establishes reboot persistence, and searches nearby networks for vulnerable servers.
How it works
- ThreatDown researchers identified the operation after finding an unauthenticated Docker registry exposed since May 2026.
- In one day, they recovered 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of data spanning October 2024 through August 2026.
- ThreatDown said in a report shared with Cyber Security News (CSN) that the finding shows how one simple configuration mistake can become a network-wide problem.
- Researchers Found a Botnet That Uses an AI Agent CARBONATO installs the open-source Hermes Agent framework without changing its software.
- entry.sh v5.3, tier 1 (Source – Threatdown) Sensitive AI API keys top the agent's list of targets, ahead of SSH credentials, access tokens, and databases.
What to take from it
This distinction matters because blocking every installation of a legitimate agent would also disrupt ordinary users. CARBONATO creates persistence through cron jobs, systemd timers, startup scripts, and OpenRC, then makes related files difficult to change. Its exposed image layers and configurations gave researchers a detailed view of the operation, underscoring the wider security risks of private container image exposure when registries lack proper access controls.
Example or evidence
- Researchers also found that the gateway advertised 12 models but served 27 through its interface.
- Infected hosts could therefore become sources of AI credentials as well as more conventional secrets, a concern also seen in malware targeting developer credentials across build environments.
- ThreatDown cited language, build timestamps, a Telegram handle, and reverse tunnels as clues pointing toward Costa Rica.
- Instead, the attackers replace its persona file with 39 lines of instructions that tell it to maintain access, collect secrets, and obey commands arriving through Telegram.
Details worth keeping
An operator's task travels with those instructions to the group's language model gateway. The model interprets the request, writes terminal commands, checks their output, and decides what to try next. The agent runs those commands on the victim server and reports back through Telegram.
Related coverage
- Smartermsp: Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain...
- Wired: Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
- Gbhackers: An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation.
- Infosecurity Magazine: Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
- Cybersecuritynews: A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print...