Threat Intelligence

New Botnet Uses AI Agent to Hijack Exposed Docker Servers

Dark Reading · 29 Sept 2026
Key Takeaway Ensure Docker management interfaces are never exposed to the public internet and rotate any AI API keys stored on your servers regularly.

Security researchers have identified a new botnet, dubbed Carbonato, that targets exposed Docker hosts. Rather than relying solely on traditional malware, the attackers install the open source Hermes Agent AI framework on compromised systems, allowing them to issue commands remotely through Telegram.

Once installed, the AI agent is used to steal AI API keys stored on the infected hosts. This gives attackers access to paid AI services at the victim's expense, and potentially exposes sensitive data tied to those accounts. The use of an AI framework to automate command execution marks a shift in how botnets are being built, making them more flexible and harder to detect using standard signatures.

Small businesses running Docker containers, particularly those with management interfaces exposed to the internet, are at risk if these systems are not properly secured. Misconfigured or internet-facing Docker hosts remain a common entry point for attackers scanning for easy targets.

botnet Docker security AI security API keys cloud infrastructure
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.