#BotNet
September 28, 2026 at 3:10 PM
x47.c Windows Botnet Uses Grok to Maintain Persistence and Features AI API Drain Capability

This article focuses heavily on the advertised capabilities of x47.c, but it minimizes the potential for zero-day exploitation or unforeseen interactions between the AI Stealth module and endpoint securi…
huntaegis.com
September 28, 2026 at 2:53 PM
🤖 Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato...

https://tinyurl.com/23cftqd9 #AINews #MachineLearning #CrustyTLDR
September 28, 2026 at 2:04 PM
Carbonatoボットネットは、Dockerホストを侵害し、Telegram制御のAIエージェントHermes Agentをデプロイします。
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Carbonato targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram to run operator-directed AI-generated commands.
thehackernews.com
September 28, 2026 at 1:40 PM
🤖 Carbonato botnet targets exposed Docker daemons, then deploys an agent framework and overwrites its SOUL.md persona with a 39-line prompt that runs Telegram-delivered tasks. Host becomes an AI-controlled node.
https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html
September 28, 2026 at 1:36 PM
După cum ziceam

Mă dai afară pe un port -> intru pe altu
Îmi banezi profilu de developer -> fac/cumpăr altele
Oprești accesul prin API pentru toată lumea -> Te scrapuiesc cu un botnet de 50K mașini cu headless selenium + sesiuni torificate de google colab #dateleMele #șeziBlând
September 28, 2026 at 1:01 PM
The Carbonato botnet exploits exposed Docker hosts to deploy AI agents that steal credentials and execute commands, posing ongoing risks to affected systems.

#infosec

Full synthesis & sources: yasna.io
New Carbonato malware uses AI agents to hijack exposed Docker hosts
The Carbonato botnet exploits exposed Docker hosts to deploy AI agents that steal credentials and execute commands, posing ongoing risks to affected systems.
yasna.io
September 28, 2026 at 1:00 PM
The CARBONATO botnet, active since October 2024, exploits exposed Docker daemons to steal credentials and fund its own LLM gateway. Discovered by ThreatDown, it uses unauthenticated connections on port 2375 to deploy a privileged container, establishing a reverse SSH tunnel to Costa Rica.
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
securityaffairs.com
September 28, 2026 at 12:50 PM
I know your botnet worm didn't come through with the last screenshot, so here you go
September 28, 2026 at 12:47 PM
Carbonato botnet targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram-controlled tasks plus reverse SSH tunneling to persist, steal credentials, and spread across networks.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 28, 2026 at 12:47 PM
Carbonato botnet targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram-controlled tasks plus reverse SSH tunneling to persist, steal credentials, and spread across networks.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 28, 2026 at 12:45 PM
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining www.securityweek.com/new-x47-c-wi...
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
www.securityweek.com
September 28, 2026 at 12:42 PM
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 28, 2026 at 12:41 PM
September 28, 2026 at 11:56 AM
It is unusual that the programs save data in this manner, but like when there's a botnet with a hundred of wifi toasters we probably wouldn't say that toasters conspired to start attacking a website, even if there is coordination
September 28, 2026 at 11:13 AM
One infected device is a problem.

Thousands controlled together become something much bigger.

That is a botnet.

Attackers control networks of compromised devices to carry out activity such as DDoS attacks, spam or malware delivery.

One controller. Many compromised devices.
September 28, 2026 at 7:30 AM
📰 Malware Carbonato Baru Memanfaatkan AI untuk Mengambil Alih Host Docker yang Terbuka

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/28/malware-carbonato-ai-hijack-docker-host/

#ai #artificialIntelligence #botnet #carbonato #container #cybersecurity #docker #dockerSecurity #h
September 28, 2026 at 4:34 AM
It’s crazy seeing a botnet work in real time in response to this post.
September 27, 2026 at 9:52 PM
befriending discord scammers so i have a living botnet to point at whoever pmo ^^
September 27, 2026 at 7:46 PM
whole lot of random followers out of nowhere again, new botnet I guess
September 27, 2026 at 7:06 PM
QTFY’s signal is the service layer, not another botnet label. DOJ said domain seizures broke essential QScan/QTRouter functions. Map the depot, not just the truck.

blog.alphahunt.io/game-theory-...
September 27, 2026 at 3:14 PM
x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining #AIcybersecurityrisks #AItechnology #Botnet
x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining
 A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks, SOCKS5 proxy access and a method designed to drain paid AI credits. According to Qrator, the malware also uses artificial intelligence to help maintain persistence on infected systems.  The botnet is advertised by a threat actor known as WraithTools. In early August, the operator offered the base x47.c package for $200, with a DDoS add-on priced at $150. The complete package, including its full range of capabilities, was offered for $950. Customers receive access to a command-and-control panel that allows them to manage infected machines and access features including fast-flux configuration, information-stealing logs, proxies, concealment capabilities and DDoS operations.  The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques. One feature specifically targets paid artificial intelligence services. The AI drain mode is designed to consume a victim’s AI credits by sending requests directly to an AI provider. The operator supplies a model name and a valid API key for accounts using OpenAI, xAI and compatible chat APIs. Because the requests are sent directly to the provider, the targeted website can remain accessible while the account’s available AI credits are depleted. x47.c also incorporates an “AI stealth” module designed to maintain persistence on compromised Windows systems.  The feature is advertised as using xAI Grok to select actions from a predefined list, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation capabilities are also available. According to Qrator, the operator activates the AI functionality by including an xAI key in the botnet build. Status messages can indicate startup changes, persistence repairs and Windows Defender exclusions. The malware also has local fallback actions that allow maintenance operations to continue when an AI model call fails.  The botnet provides operators with additional control over infected systems. They can select DDoS targets and download, update or remove software from compromised hosts. A rootkit module is also promoted for removing artifacts associated with rival malware. Beyond DDoS activity, x47.c can harvest passwords and cookies from browsers, along with Discord tokens, cryptocurrency wallet data and AI-service tokens.  Its SOCKS5 module allows compromised systems to relay traffic, while operators can monitor proxy connections and review their health status and timeouts. The combination of AI-assisted persistence, credential theft, proxy capabilities, DDoS functions and AI credit draining makes x47.c a broad Windows botnet offering multiple ways to abuse compromised systems and online services.
dlvr.it
September 27, 2026 at 3:12 PM
I'm not pretending to not know, I just don't care. Somebody waited until the K-Pop fans didn't have anything to put on repeat to activate their botnet/payola campaign. Big deal.
September 27, 2026 at 3:00 PM