CARBONATO Botnet Deployed AI Agents Into Docker Servers
Researchers identified a new botnet using AI agents within compromised Docker environments.
Updated on Sept. 25, 2026 in Artificial Intelligence

Live Poll
Do you believe the use of AI in cyberattacks makes your personal data less secure?
Researchers identified a botnet dubbed CARBONATO that infiltrates internet-exposed Docker servers. The campaign deploys autonomous AI agents within compromised systems to execute tasks controlled via Telegram.
Why it matters
The integration of AI agents into botnet infrastructure creates a new vector for automating unauthorized tasks within containerized environments. This development highlights the persistent security risks of leaving Docker services exposed without authentication.
The botnet operates by scanning for Docker services exposed to the internet without authentication. Once identified, the attackers launch a privileged container, providing the necessary permissions to gain control of the host machine.
The players
CARBONATO
A botnet that exploits unsecured Docker services to deploy AI agents for automated operations.
Docker
A platform for developing, shipping, and running applications in isolated environments known as containers.
Telegram
A cloud-based messaging platform used by attackers as a command-and-control channel for botnet management.
The details
The CARBONATO botnet functions by exploiting Docker services that lack security authentication. Upon successful infiltration, the attackers launch a privileged container—a container with elevated host system permissions—which allows the botnet to gain unauthorized access to the underlying host. The botnet then deploys an AI agent, a software entity capable of performing complex automated tasks within the system. Operators manage these operations through Telegram, using the messaging platform as a command-and-control interface to send instructions and retrieve results.
Timeline
September 25, 2026: Researchers published the report on the CARBONATO botnet.
The Tech Race
This development represents a shift from traditional automated botnet scripts to the integration of autonomous AI agents within containerized infrastructure. The ability to manage these agents via messaging platforms illustrates a new phase in the race between automated threat detection and agent-based infiltration.
Administrators managing containerized environments must ensure Docker services are not exposed to the internet without proper authentication protocols. This security measure prevents the unauthorized deployment of privileged containers that allow botnet operators to execute code on host machines.
The takeaway
The deployment of AI agents within botnets signifies an increased threat to misconfigured container services that lack basic authentication. Security professionals should monitor for unauthorized privileged containers and audit all internet-facing Docker management ports.
Further reading
For more on the intersection of security and machine learning, visit Artificial Intelligence.
Live Poll
Do you believe the use of AI in cyberattacks makes your personal data less secure?





