Opens in a new tab

CARBONATO Botnet Uses AI Inside Docker Servers

Botnet exploits exposed Docker to deploy AI agent for post-compromise tasks

The CARBONATO botnet is compromising internet-exposed Docker services and installing an AI agent that can carry out operator instructions. The campaign combines automated propagation with AI-assisted activity inside infected servers.

ThreatDown researchers found that the operation can launch privileged containers, gain access to the underlying host, survive reboots and search nearby networks for more exposed systems. The findings, reported on 25 September 2026, show how a single unauthenticated Docker service can provide an entry point for broader compromise.

How the CARBONATO botnet compromises Docker

The initial access method is straightforward. CARBONATO looks for Docker services that have been exposed to the public internet without authentication, allowing the attackers to interact with them without first stealing a password or exploiting a software flaw.

Once access is available, the botnet launches a privileged container. Privileged containers receive extensive access to host resources, so running one through an exposed Docker service can allow an attacker to move beyond the container and take control of the server beneath it.

CARBONATO then establishes persistence so that its components continue operating after the server reboots. It also examines networks reachable from the compromised host, looking for additional vulnerable Docker services that can be infected.

This propagation does not depend on an operator issuing fresh instructions for every target. The automated spreading component can continue searching for and compromising exposed services, while a separate operator-controlled agent performs tasks on systems that are already infected.

A configuration failure rather than a disclosed CVE

The available reporting does not identify a Docker vulnerability, CVE or affected software version. Instead, the campaign relies on Docker services being reachable from the internet without authentication and then permitting the creation of a privileged container.

As a result, the potentially affected population is not defined by a particular Docker release. Any organisation exposing a Docker service in the manner described could be at risk, regardless of sector or business size. ThreatDown did not disclose a confirmed victim count or list of affected organisations.

CARBONATO botnet evidence recovered by researchers

ThreatDown identified the operation after discovering an unauthenticated Docker registry that had been exposed since May 2026. The registry provided researchers with an unusually detailed collection of files and container artefacts connected to the campaign.

During a single day of collection, the researchers recovered:

  • 59 repositories associated with the exposed registry.
  • 234 container image tags.
  • 605 verified data blobs.
  • Approximately 4.3 GB of data.

The recovered material covered activity from October 2024 through August 2026. This span does not by itself confirm that every component was continuously active throughout that period, but it gives researchers a substantial record of the tools and infrastructure used by the CARBONATO botnet.

The registry exposure also illustrates the same underlying security problem that enables the campaign. Services holding operational data or accepting administrative commands can reveal sensitive material when they are published without effective access controls.

What is known about current exploitation

The research describes a functioning botnet with automated spreading capabilities and an operator channel for actions inside compromised hosts. The collected artefacts extend through August 2026, shortly before the findings were reported.

However, the public information does not specify how many Docker servers were compromised, which countries were affected or whether particular industries were targeted. It also does not identify specific organisations or confirm exploitation after August 2026. The evidence therefore supports active campaign infrastructure and real compromise methods, but not a precise measure of the botnet’s current size.

How the AI agent operates inside infected servers

The distinctive feature of the CARBONATO botnet is its use of Hermes Agent, an open-source AI agent framework. According to the researchers, the attackers install the framework without modifying its underlying software.

Instead, they replace its persona file with 39 lines of instructions. Those instructions direct the agent to maintain access, collect secrets and follow commands delivered through Telegram.

When an operator sends a task, the request and the attacker’s instructions are passed to the group’s language model gateway. The model interprets the request, produces terminal commands, examines the resulting output and decides what action to attempt next.

The agent executes those commands directly on the victim server and returns the results through Telegram. This gives the operator an interactive interface while allowing the AI system to translate higher-level requests into technical steps.

The AI component should not be confused with the botnet’s automated propagation. CARBONATO can search for additional exposed Docker services without receiving new instructions, while the AI agent supports post-compromise operations on machines that have already been breached.

Credential collection and continued access

The persona instructions specifically tell the agent to collect sensitive credentials and preserve access. Depending on what is available to the compromised host, credentials could expose other systems and services reachable from that machine.

The reporting does not detail every command issued by operators or every type of secret collected. Nevertheless, an agent able to run terminal commands, review their output and adapt its next action can reduce the amount of manual work required to investigate a compromised environment.

Why the CARBONATO botnet matters

CARBONATO demonstrates that attackers do not always need a sophisticated software exploit. An unauthenticated management service can be enough to start a sequence that reaches the host, survives a reboot and spreads to other accessible systems.

The use of an unmodified open-source AI framework is also significant. The attackers appear to have changed the agent’s behaviour through a short persona file rather than developing a specialised AI platform. This lowers the technical effort required to add AI-assisted command execution to an established botnet workflow.

Telegram provides the communication path between the operator and agent, while the language model gateway interprets requests. Blocking one visible component may therefore be insufficient if the privileged container, persistence mechanism or exposed Docker service remains in place.

Actions for organisations running Docker

Organisations should first establish whether any Docker services or registries are reachable from the public internet without authentication. The response should focus on the conditions used by this campaign and on signs that privileged containers have already been launched.

  • Remove unnecessary public exposure from Docker APIs, services and registries.
  • Require authentication and restrict management access to approved systems and networks.
  • Review containers for unexpected privileged settings and investigate unfamiliar images, repositories or startup scripts.
  • Check hosts for persistence that survives reboot and for unexplained connections to Telegram or language model services.
  • Rotate credentials stored on or accessible from a suspected host, after containing and examining the compromise.
  • Inspect nearby systems for exposed Docker services because CARBONATO can spread laterally without new operator commands.

Simply deleting a suspicious container may not remove the infection if the CARBONATO botnet has already reached the host and established persistence. Investigation should cover both the container environment and the underlying server.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call