Carbonato Malware Exploits Exposed Docker Hosts with AI-Powered Botnet A new malware campaign called Carbonato is exploiting Docker hosts with exposed APIs to build an AI-powered botnet, according to the report. Carbonato targets Docker daemons with exposed APIs, using them to launch a privileged container and gain broad access to the host. Meet Carbonato, a sneaky new malware campaign that's taking advantage of exposed Docker hosts to build an AI-powered botnet, and discover how it compromises vulnerable systems with ease. It targets Docker daemons with exposed APIs, using them to launch a privileged container and gain broad access to the host.