Malwarebytes' ThreatDown researchers identified a new botnet, Carbonato, that scans for Docker hosts with unauthenticated APIs on port 2375 and hijacks them via privileged containers. The malware installs SSH backdoors, sets up multiple persistence mechanisms, and deploys the Hermes Agent AI framework under an agent named GH0ST to execute operator commands and exfiltrate credentials and API keys via Telegram. The findings came from an unauthenticated Docker registry containing nearly 60 repositories and 4.3GB of data spanning operations from October 2024 to August 2026.
bleepingcomputer.com
· 2026-09-24
Cisco Talos researchers identified Windows malware named CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to decide its next actions on infected machines, continuing to function if one service goes down. The tool, designed to steal credentials and cryptocurrency, has no built-in mechanism for human operators to issue commands directly, and Talos linked it to 2025 credit-card fraud forum activity, though the creator and any real-world targets remain unidentified.
techspot.com
· 2026-09-23
Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.
wired.com
· 2026-09-22