← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 25, 2026 · 14:17via Cyber Security News

Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers

Brief

CARBONATO is a botnet that turns Docker servers into footholds for attackers. It places an AI agent inside compromised systems, letting operators send tasks through Telegram and receive results.

The campaign begins with Docker services carelessly exposed to the internet without authentication. Once inside, CARBONATO launches a privileged container, gains access to the host, establishes reboot persistence, and searches nearby networks for vulnerable servers.

ThreatDown researchers identified the operation after finding an unauthenticated Docker registry exposed since May 2026.

In one day, they recovered 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of data spanning October 2024 through August 2026.

ThreatDown said in a report shared with Cyber Security News (CSN) that the finding shows how one simple configuration mistake can become a network-wide problem.

Read more on Cyber Security News→