Skip to content

company

ThreatDown

Security research outfit cited by Sophos as having documented a similar Deno-based intrusion chain delivering Castle RAT.

Known aliases

  • Threatdown
  • ThreatDown by Malwarebytes

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

CARBONATO botnet infects Docker hosts, prioritizing theft of AI provider API keys

CARBONATO, a Docker botnet running since October 2024, hijacks hosts on open port 2375 and steals keys from 14 AI providers to fund its own LLM gateway. ThreatDown found the crew's own container registry exposed, handing defenders 4.3 GB of its toolchain.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence60