ThreatDown says the Carbonato worm breaks into Docker daemons open on port 2375 and installs the open-source Hermes AI agent, then rescans nearby networks every five minutes to spread. An operator drives each infected host over Telegram.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence50
CARBONATO, a Docker botnet running since October 2024, hijacks hosts on open port 2375 and steals keys from 14 AI providers to fund its own LLM gateway. ThreatDown found the crew's own container registry exposed, handing defenders 4.3 GB of its toolchain.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
The chain in OpenAI's post-mortem on the Hugging Face incident runs through a RubyGems processing bug, an HDF5 dataset file and 14 write tokens that were already public, according to Pillar Security's Dor Sarig. OpenAI calls the result a warning shot.
Reality
- Evidence38
- Adoption30
- Hype gap+25
- Incentives80
- Confidence42
ThreatDown says the crime storefront Kriminal.ai is just Grok with the safety layer stripped off. That moves the control you depend on from your stack to someone else's.
Reality
- Evidence42
- Adoption30
- Hype gap+24
- Incentives72
- Confidence45
ThreatDown says Kriminal, one of the newest crimeware AI tools, is a storefront and a jailbreak prompt on rented models, sold on the open web from $12.99 a month.
Reality
- Evidence58
- Adoption34
- Hype gap+12
- Incentives68
- Confidence52
Attackers installed a legitimate JavaScript and TypeScript runtime on victim hosts to run payloads in memory. The middle of the chain barely varied, which is where detection work belongs.
Reality
- Evidence62
- Adoption41
- Hype gap+12
- Incentives58
- Confidence55