$ techbeacon▋
CVE & Exploits

AI-Driven CARBONATO Botnet Hijacks Docker Daemons to Finance Its Own Language Model Service

AI-Driven CARBONATO Botnet Hijacks Docker Daemons to Finance Its Own Language Model Service

Security researchers have identified a novel botnet, dubbed CARBONATO, that leverages artificial‑intelligence techniques to infiltrate vulnerable Docker installations, exfiltrate cloud credentials and use the stolen assets to pay for its own large‑language‑model (LLM) gateway.

The operation came to light after the threat‑intel firm ThreatDown traced anomalous traffic patterns to a series of compromised Docker daemons. Their investigation revealed that the malicious infrastructure has been active since at least October 2024, indicating a sustained campaign that has gone largely undetected until now.

CARBONATO exploits Docker hosts that expose the Docker Engine API without authentication, a misconfiguration that still appears in many cloud‑native environments. Once it gains access, the botnet drops a lightweight AI agent capable of autonomous command execution. The agent scans for stored API keys, cloud access tokens and other secrets, siphons them to a command‑and‑control server and then uses the harvested credentials to purchase compute credits for an LLM service that it operates as a revenue stream.

Beyond credential theft, the botnet’s self‑funding model poses a double threat. The stolen keys enable further lateral movement across victim networks, while the revenue generated from the LLM gateway can be reinvested to expand the botnet’s reach, purchase additional infrastructure or even develop more sophisticated attack modules.

The emergence of CARBONATO reflects a broader trend where threat actors embed AI capabilities directly into malware. By automating decision‑making, such tools can adapt to diverse environments, prioritize high‑value targets and reduce the need for human operators. Analysts note that similar AI‑enhanced tactics have been observed in ransomware extortion and phishing campaigns, underscoring a shift toward more autonomous cyber‑crime ecosystems.

Security experts advise organizations to audit Docker deployments for exposed APIs, enforce strict authentication, and segment container workloads from critical assets. Regular rotation of cloud credentials, implementation of zero‑trust networking principles and continuous monitoring for unusual outbound traffic are also recommended to mitigate the risk posed by CARBONATO and comparable threats.

As the botnet continues to evolve, researchers expect it to refine its AI modules and potentially target other container orchestration platforms. Ongoing collaboration between industry partners and threat‑intel communities will be crucial to track the botnet’s activity, develop detection signatures and disrupt its funding loop before it can scale further.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related