CARBONATO: a botnet built around an AI agent
CARBONATO is a Docker-based botnet discovered by ThreatDown researchers that exploits exposed Docker daemons on port 2375. It operates through an unauthenticated Docker registry exposed since May 2026, facilitating both the distribution of trojanized cryptocurrency wallet applications and botnet activities. The botnet uses a modified Hermes Agent, an open-source AI framework, to execute commands via Telegram, maintain persistence, and steal credentials. The campaign infrastructure spans multiple hosting providers and has been active from October 2024 through August 2026. No specific software versions are identified as affected, and no CVE or patch information is available.
AI Analysis
Technical Summary
CARBONATO is a botnet targeting exposed Docker daemons on port 2375, discovered via an unauthenticated Docker registry. It distributes trojanized cryptocurrency wallets and operates a botnet infrastructure leveraging a modified Hermes Agent AI framework. This AI agent is customized with prompts to execute commands through Telegram, maintain persistence on infected hosts, and harvest credentials. The botnet infrastructure is distributed across several hosting providers including Linode, Hetzner, and Contabo, with documented activity spanning nearly two years. No direct exploit code or CVE identifiers are associated with this threat, and no patch or remediation details are provided.
Potential Impact
The botnet enables attackers to compromise Docker hosts with exposed daemons, leading to credential theft and unauthorized command execution via Telegram. The distribution of trojanized cryptocurrency wallets poses additional risk of financial theft. The persistence mechanisms and credential harvesting capabilities increase the potential for prolonged unauthorized access and lateral movement within compromised environments. The medium severity reflects the combination of credential theft and botnet control capabilities, but no known exploits in the wild or direct CVEs are reported.
Mitigation Recommendations
No official patch or remediation is provided. Organizations should ensure Docker daemons are not exposed on public or untrusted networks, especially on port 2375, which is known to be insecure when unauthenticated. Restrict access to Docker APIs using authentication and network controls. Monitor for unauthorized Docker registry access and suspicious network activity involving Telegram command execution. Since no vendor advisory or patch information is available, follow best practices to secure Docker environments and remove any unauthorized containers or agents.
Indicators of Compromise
- ip: 213.136.79.115
- ip: 213.136.79.115
- ip: 190.211.124.187
- ip: 190.211.124.187
- ip: 91.99.195.164
CARBONATO: a botnet built around an AI agent
Description
CARBONATO is a Docker-based botnet discovered by ThreatDown researchers that exploits exposed Docker daemons on port 2375. It operates through an unauthenticated Docker registry exposed since May 2026, facilitating both the distribution of trojanized cryptocurrency wallet applications and botnet activities. The botnet uses a modified Hermes Agent, an open-source AI framework, to execute commands via Telegram, maintain persistence, and steal credentials. The campaign infrastructure spans multiple hosting providers and has been active from October 2024 through August 2026. No specific software versions are identified as affected, and no CVE or patch information is available.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CARBONATO is a botnet targeting exposed Docker daemons on port 2375, discovered via an unauthenticated Docker registry. It distributes trojanized cryptocurrency wallets and operates a botnet infrastructure leveraging a modified Hermes Agent AI framework. This AI agent is customized with prompts to execute commands through Telegram, maintain persistence on infected hosts, and harvest credentials. The botnet infrastructure is distributed across several hosting providers including Linode, Hetzner, and Contabo, with documented activity spanning nearly two years. No direct exploit code or CVE identifiers are associated with this threat, and no patch or remediation details are provided.
Potential Impact
The botnet enables attackers to compromise Docker hosts with exposed daemons, leading to credential theft and unauthorized command execution via Telegram. The distribution of trojanized cryptocurrency wallets poses additional risk of financial theft. The persistence mechanisms and credential harvesting capabilities increase the potential for prolonged unauthorized access and lateral movement within compromised environments. The medium severity reflects the combination of credential theft and botnet control capabilities, but no known exploits in the wild or direct CVEs are reported.
Defensive Guidance
No official patch or remediation is provided. Organizations should ensure Docker daemons are not exposed on public or untrusted networks, especially on port 2375, which is known to be insecure when unauthenticated. Restrict access to Docker APIs using authentication and network controls. Monitor for unauthorized Docker registry access and suspicious network activity involving Telegram command execution. Since no vendor advisory or patch information is available, follow best practices to secure Docker environments and remove any unauthorized containers or agents.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.threatdown.com/blog/carbonato/"]
- Pulse Id
- 6ab4d79db2222977d275954f
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip213.136.79.115 | — | |
ip213.136.79.115 | CC=DE ASN=AS51167 contabo gmbh | |
ip190.211.124.187 | — | |
ip190.211.124.187 | CC=CR ASN=AS262145 cooperativa de electrificacin rural de san carlos r.l. (coopelesca r.l.) | |
ip91.99.195.164 | CC=IR ASN=AS16322 pars online pjs |
Threat ID: 6ab4d935f7a7c541060e35e6
Added to database: 09/24/2026, 08:03:01 UTC
Last enriched: 09/24/2026, 08:20:16 UTC
Last updated: 09/24/2026, 09:07:21 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.