← Back to feed
AI SecurityEmerging1 sourceSep 25, 2026 · 09:55via Security Affairs

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

Brief

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution.

CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain and revealed details about how the botnet operates.

In just one day of passive, read-only collection, researchers gathered 4. 3 GB of image data, including 59 repositories, 234 tags, and 605 verified file blobs. The registry also exposed the configuration history of the images, revealing command-and-control addresses, bot tokens, and even the shared password for the attackers’ own AI gateway.

Read more on Security Affairs→