{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/threatdown-carbonato-agent-botnet-2026/",
 "asOf": "2026-09-26",
 "id": "threatdown-carbonato-agent-botnet-2026",
 "date": "2026-09-22",
 "datePrecision": "day",
 "title": "ThreatDown finds Carbonato, a Docker botnet that installs an AI agent to run operators’ tasks",
 "lane": "attack",
 "kind": "malware",
 "summary": "ThreatDown reports a botnet that compromises Docker hosts with unauthenticated APIs, installs the open-source Hermes Agent framework with a replaced persona file, and has the agent carry out tasks sent over Telegram, including collecting AI API keys and other credentials. ThreatDown recovered the operation's toolchain from an exposed registry, with images dating from October 2024 to August 2026, and describes the agent reading command output and deciding next steps in an operator-driven loop.",
 "whyItMatters": "It shows an off-the-shelf agent framework used as a botnet implant, with AI API keys treated as a primary theft target.",
 "actors": [
  "threatdown"
 ],
 "topics": [
  "ai-malware",
  "ai-enabled-intrusion"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.threatdown.com/blog/carbonato/",
   "publisher": "ThreatDown",
   "title": "CARBONATO: a botnet built around an AI agent (page dated September 22; metadata says September 23)",
   "date": "2026-09-22",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/",
   "publisher": "BleepingComputer",
   "title": "New Carbonato malware uses AI agents to hijack exposed Docker hosts",
   "date": "2026-09-24",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "The exposed registry held 59 repositories, 234 image tags and 4.3 GB of image data.",
   "locator": "Findings table"
  },
  {
   "fact": "The agent’s prompt directs it to collect AI API keys from 14 providers ahead of SSH credentials and access tokens.",
   "locator": "Findings table"
  },
  {
   "fact": "Scripts, not the agent, spread the botnet by scanning attached networks for exposed Docker daemons. ThreatDown did not attribute it to a known cluster but assesses the operators as likely in Costa Rica.",
   "locator": "Article body; BleepingComputer"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "runtime-llm-malware"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}