ainotis Join
My notis

Checked fact 18628 Sep 2026Research

It spreads by scanning for Docker hosts with an API exposed on port 2375 without authentication.

The exact words it rests on

Docker daemons that accept unauthenticated connections on port 2375

What the source said when we opened it, on 28 Sep 2026.

The source

CARBONATO: a botnet built around an AI agent
ThreatDown (Malwarebytes) · 2026-09-22

Checked

Checked by the notis newsroom on , against the source above.

In the story

ThreatDown says the CARBONATO botnet installs an unmodified Hermes Agent and targets AI API keys first. 28 Sep 2026

Cite this fact

Anyone may quote this address. It does not change; if we correct the story, this page says so.