CARBONATO Botnet Deployed AI Agents Into Docker Servers

The newly identified botnet uses compromised Docker services to run malicious AI agents via Telegram.

Updated on Sept. 25, 2026 in Artificial Intelligence

CARBONATO Botnet Deployed AI Agents Into Docker Servers

Live Poll

Do you believe the use of AI in cyberattacks makes your personal data less secure?

Security researchers have identified a new botnet named CARBONATO that compromises exposed Docker servers to deploy AI agents. Operators control these malicious agents remotely using the Telegram messaging platform.

Why it matters

The campaign highlights the growing security risks faced by organizations with internet-exposed services that lack proper authentication protocols. By leveraging AI agents, attackers can potentially automate complex tasks within compromised host environments.

The botnet infiltrates Docker services that are exposed to the internet without authentication. Once inside, the malware launches a privileged container to establish host-level access for its AI-driven tasks.

The players

CARBONATO

This is a newly discovered botnet that utilizes compromised Docker servers to execute AI-driven tasks.

Telegram

This cloud-based messaging platform serves as the command-and-control interface for the botnet operators.

The details

The CARBONATO botnet operates by scanning for and exploiting unsecured Docker services on the public internet. After gaining initial access, the botnet executes a privileged container, granting the attackers control over the host system to run AI-powered tasks managed through Telegram.

Timeline

  1. September 25, 2026: Researchers reported the discovery of the CARBONATO botnet.

The Tech Race

The emergence of CARBONATO underscores the critical need for strict authentication in Docker containers to prevent unauthorized host-level access. This development signals a shift where attackers are moving beyond simple data theft to deploying complex, automated AI agents within enterprise environments.

Organizations must immediately audit their Docker instances to ensure they are not exposed to the public internet without robust authentication. Implementing these security protocols is essential to prevent attackers from establishing privileged access to critical server infrastructure.

The takeaway

Security teams should prioritize restricting network access to container management ports to mitigate the risk of automated compromises. This incident serves as a warning that standard misconfigurations can now serve as gateways for sophisticated AI-enabled operations.

Further reading

For more background on the evolving landscape of automated threats, visit our Artificial Intelligence section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you believe the use of AI in cyberattacks makes your personal data less secure?

CARBONATO Botnet Deployed AI Agents Into Docker Servers