A new cloud-targeting botnet called Cloud AI Infrastructure Attack Framework (CAI) has emerged, designed to steal credentials and mine cryptocurrency while actively eliminating competing malware like TeamPCP and PCPJack from compromised systems. It targets cloud-native tools such as Docker, Kubernetes, and Redis, using a centralized command-and-control structure and showing signs of LLM-assisted development. Security researchers warn that CAI's emergence alongside rival threat actors signals a growing and increasingly competitive landscape of malicious actors targeting cloud infrastructure and developer secrets.