Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons

Cyber Security Agency of Singapore Version 1 original current

Imported from official source

Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker environments are advised to review their configurations and assess potentially exposed systems for signs of compromise.

This version

Version
1 of 1
Recorded
October 03, 2026 20:41
Change
Initial
Content hash
c2d33a9e0850116ee207e52471160ca8
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.