CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet.
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
About this summary. This is a short, independently written summary of an article first published by Security Affairs. Cyber Security News did not report or verify the underlying story. Read the original: https://securityaffairs.com/199716/malware/ai-powered-carbonato-botnet-steals-credentials-to-fund-its-own-llm-gateway.html

Source attribution: headline and facts are from Security Affairs (securityaffairs.com). Summary method: excerpt of the source description. See our source attribution policy.





