Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons
30 September 2026
Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker environments are advised to review their configurations and assess potentially exposed systems for signs of compromise.
Background
Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet, typically over TCP port 2375.
After identifying an exposed Docker API, CARBONATO uses legitimate Docker functionality to create a privileged container with access to the host filesystem, processes and network. This allows the attacker to execute commands on the underlying host.
Following successful compromise, the botnet establishes persistent remote access, steals credentials and other sensitive information, and scans connected networks for additional exposed Docker hosts.
CARBONATO also periodically scans networks accessible from compromised hosts for other Docker daemons exposed on port 2375 and attempts to compromise them, allowing the botnet to propagate across affected environments.
Affected Systems
Docker hosts may be at risk where the Docker Remote API is accessible from the Internet or other untrusted networks without authentication, particularly where the Docker daemon is listening on port 2375.
Indicators of Compromise
Known indicators of compromise associated with the CARBONATO campaign are available at: https://www.threatdown.com/blog/carbonato/ (opens in new tab)
Recommendations
Users and administrators are advised to:
Restrict access to the Docker Remote API. Do not expose the Docker daemon directly to the Internet or other untrusted networks. Where remote access is not required, disable network access to the Docker daemon.
Secure required remote access. Where remote access to the Docker daemon is necessary, use secure mechanisms such as SSH or TLS with client authentication, and restrict access to authorised systems and users.
Assess potentially exposed systems for compromise. Review Docker hosts that have exposed unauthenticated Docker APIs for unexpected privileged containers, suspicious processes, persistence mechanisms, unauthorised SSH configurations and the indicators of compromise.
Review and rotate potentially exposed credentials. If compromise is suspected or confirmed, organisations should identify and rotate credentials accessible from affected systems, including API keys, access tokens, SSH keys and other secrets.
Monitor for lateral propagation. Review network logs for unusual scanning activity targeting TCP port 2375, particularly from Docker hosts, as compromised systems may attempt to identify and compromise other exposed Docker daemons on connected networks.
Organisations that identify signs of compromise should isolate affected systems and conduct further investigation and remediation before restoring them to service.
References
https://www.threatdown.com/blog/carbonato/ (opens in new tab)
https://docs.docker.com/engine/security/protect-access/ (opens in new tab)
