Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
CARBONATO infects exposed Docker hosts, persists, spreads to nearby daemons, and runs a Telegram-controlled AI agent.
ThreatDown describes CARBONATO, a botnet that compromises Docker daemons left exposed to the internet without authentication, starts a privileged container, and gains host access. It opens a reverse SSH tunnel, persists through cron, systemd, and related mechanisms, and every five minutes scans attached /24 ranges for more exposed Docker services. Operators install the unmodified Hermes Agent with a short persona that collects AI API keys, SSH credentials, tokens, and database secrets, then runs commands from tasks sent over Telegram. Researchers recovered an exposed registry with 59 repositories and about 4.3 GB of images spanning October 2024 to August 2026; clues point toward Costa Rica, but attribution is not confirmed.