Summary
Cado Security has published analysis of Carbonato, a malware family that uses embedded AI agent logic to autonomously discover, assess, and compromise internet-exposed Docker API endpoints at scale without requiring a human operator to direct individual exploitation steps. Unlike prior cryptomining malware that scanned for exposed Docker daemons using fixed exploitation scripts, Carbonato uses an AI agent decision layer to evaluate each discovered Docker host, select appropriate exploitation techniques based on the host’s observed configuration, deploy payloads, and establish persistence — adapting its approach when initial techniques fail. Carbonato’s primary payload is a cryptomining agent, but its lateral movement capability allows it to pivot from compromised Docker hosts into connected container orchestration infrastructure and internal networks.
Timeline
| Date | Event |
|---|---|
| August-September 2026 | Carbonato campaign observed in Cado Security honeypot telemetry; AI agent-driven exploitation of exposed Docker APIs captured |
| Sep 23, 2026 | Cado Security publishes full Carbonato technical analysis; BleepingComputer reports |
What Happened
Exposed Docker daemon APIs — Docker’s management interface left accessible on TCP port 2375 or 2376 without authentication — have been a persistent target for cryptomining malware since at least 2019. Previous campaigns used fixed exploitation scripts: scan for port 2375, attempt to create a privileged container, mount the host filesystem, drop a miner. Defenders became familiar with this pattern and detection coverage improved accordingly.
Carbonato replaces the fixed script with an AI agent that reasons about each host before acting. When Carbonato’s scanner identifies an exposed Docker API, it passes the host’s observed configuration — Docker version, running containers, available images, network configuration, and resource profile — to an embedded AI decision module. The module selects an exploitation approach from available techniques, monitors whether it succeeded, and selects an alternative if it failed. Cado Security observed Carbonato attempting at least three distinct container escape and persistence techniques across different hosts in the same campaign, with technique selection driven by host-specific observations rather than a fixed sequence. Once established on a Docker host, Carbonato deploys a cryptomining payload and scans for adjacent Kubernetes API servers and Docker Swarm management nodes, attempting to extend its foothold to additional nodes if reachable orchestration infrastructure is found.
Domain Intelligence
docker.com — 62.39
docker.com scores in the low-trust range at 62.39. Docker is the vendor of the container runtime platform targeted in the Carbonato campaign. One threat intelligence source has flagged docker.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 24, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026