Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
NadMesh Botnet Harvests 3,800+ Cloud Credentials by Targeting Exposed AI Services
00

NadMesh Botnet Harvests 3,800+ Cloud Credentials by Targeting Exposed AI Services

Jul 17, 2026

The Go-based NadMesh botnet, discovered in early July 2026, is systematically targeting exposed AI services like ComfyUI, Ollama, and Gradio to harvest cloud credentials. According to QiAnXin's XLab, the botnet's dashboard claims the theft of 3,811 unique AWS keys. NadMesh exploits unauthenticated Model Context Protocol (MCP) deployments, Docker APIs, and Jenkins consoles to extract sensitive configuration files and Kubernetes tokens, highlighting a critical shadow IT security gap in rapid AI deployments.

NadMesh botnet operations

  • ▪The Go-based NadMesh botnet emerged in early July 2026 as a long-lived, iteratively developed botnet coordinating large numbers of bots via attacker-controlled VPS nodes.
  • ▪The NadMesh botnet's central controller coordinates bots using HTTP APIs, seeding them with more than 90 cloud provider address ranges and falling back to random /24 ranges when the task queue is empty.
  • ▪The NadMesh botnet automatically blacklists any target that absorbs ten deployment attempts without returning a result, classifying it as a suspected honeypot.
  • ▪The NadMesh botnet utilizes a Shodan harvester to continuously scan for exposed AI services, including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio.

Exposed AI service vulnerabilities

  • ▪The Model Context Protocol (MCP) specification left authentication outside the core protocol, and the authorization flow added in March 2025 remains optional.
  • ▪The NadMesh botnet prioritizes exploiting Model Context Protocol (MCP) services over Kubernetes and Docker APIs, utilizing a JSON-RPC tools/call to execute commands.
  • ▪Censys identified 12,520 reachable Model Context Protocol (MCP) services across 8,758 IP addresses as of April 28, 2026, which grew to over 21,000 by May 6, 2026.

Cloud credential harvesting

  • ▪The NadMesh botnet's intelligence feed recorded 47 credential hauls and 41 model inventories containing DeepSeek, GLM, and Kimi identifiers tagged with ':cloud'.
  • ▪The NadMesh botnet operator's dashboard, analyzed by QiAnXin's XLab, claims the collection of 3,811 unique AWS keys.
  • ▪The NadMesh botnet targets configuration files and environment variables to harvest cloud keys, Kubernetes service account tokens, and the contents of ~/.aws/config, .env, and ~/.docker/config.json.

Exploitation vectors

  • ▪The NadMesh botnet's exploit traffic targets CVE-2026-39987 in Marimo notebooks and CVE-2026-41176 in rclone RC servers.
  • ▪The NadMesh botnet deploys more than 20 exploitation vectors, including Kubernetes API abuse via pods with hostPath mounts and Docker API misuse to launch containers with host networking.
  • ▪QiAnXin's XLab observed that docker_containers_api_rce accounted for 30.31% of NadMesh's exploit traffic, while jenkins_scripttext_rce accounted for 22.28%.

Remediation procedures

  • ▪If a host is compromised by NadMesh, organizations must isolate the host, pull the three-way persistent agent, and revoke all visible credentials including AWS keys and cluster tokens.
  • ▪Security recommendations to mitigate NadMesh include restricting public access to Docker APIs, Jenkins consoles, and securing ports 8188, 11434, 7860, and 5678.

5 sources

Cyberwebspider
NadMesh Botnet Exploits AI Services for Cloud Credentials
View source article
News
NadMesh Botnet Exposes the AI Shadow IT Crisis: 3,800+ AWS Keys at Risk
View source article
Cyberpress
NadMesh Botnet Targets AI and MCP Servers With 20+ Remote Code Execution Vectors
View source article
Thehackernews
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
View source article
Cybersixt
New NadMesh botnet hijacks AI services to steal cloud credentials
View source article

Featured stories

View more in Cloud security

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

DeepSeek releases software tools for Huawei AI chips to challenge Nvidia

Sep 30, 2026 · 4 sources

Story comments

Loading comments…

Related Projects

Open WebUIn8nOllamaLangflowComfyUIGradioAmazon Web Services

Topics

Cloud securityAI tools & productsAI securityAI privacy & surveillance

Featured stories

View more in Cloud security

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

DeepSeek releases software tools for Huawei AI chips to challenge Nvidia

Sep 30, 2026 · 4 sources