CARBONATO Botnet Deployed AI Agents Into Docker Servers
The newly identified botnet uses compromised Docker services to run malicious AI agents via Telegram.
Updated on Sept. 25, 2026 in Artificial Intelligence

Live Poll
Do you believe the use of AI in cyberattacks makes your personal data less secure?
Security researchers have identified a new botnet named CARBONATO that compromises exposed Docker servers to deploy AI agents. Operators control these malicious agents remotely using the Telegram messaging platform.
Why it matters
The campaign highlights the growing security risks faced by organizations with internet-exposed services that lack proper authentication protocols. By leveraging AI agents, attackers can potentially automate complex tasks within compromised host environments.
The botnet infiltrates Docker services that are exposed to the internet without authentication. Once inside, the malware launches a privileged container to establish host-level access for its AI-driven tasks.
The players
CARBONATO
This is a newly discovered botnet that utilizes compromised Docker servers to execute AI-driven tasks.
Telegram
This cloud-based messaging platform serves as the command-and-control interface for the botnet operators.
The details
The CARBONATO botnet operates by scanning for and exploiting unsecured Docker services on the public internet. After gaining initial access, the botnet executes a privileged container, granting the attackers control over the host system to run AI-powered tasks managed through Telegram.
Timeline
September 25, 2026: Researchers reported the discovery of the CARBONATO botnet.
The Tech Race
The emergence of CARBONATO underscores the critical need for strict authentication in Docker containers to prevent unauthorized host-level access. This development signals a shift where attackers are moving beyond simple data theft to deploying complex, automated AI agents within enterprise environments.
Organizations must immediately audit their Docker instances to ensure they are not exposed to the public internet without robust authentication. Implementing these security protocols is essential to prevent attackers from establishing privileged access to critical server infrastructure.
The takeaway
Security teams should prioritize restricting network access to container management ports to mitigate the risk of automated compromises. This incident serves as a warning that standard misconfigurations can now serve as gateways for sophisticated AI-enabled operations.
Further reading
For more background on the evolving landscape of automated threats, visit our Artificial Intelligence section.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you believe the use of AI in cyberattacks makes your personal data less secure?







