NadMesh is a Go-based botnet and autonomous attack platform focused on exposed cloud, container, and AI infrastructure, particularly services associated with the Model Context Protocol ecosystem and self-hosted AI tooling. Observed since early July 2026, it combines internet-scale scanning, automated exploitation, persistence, credential theft, and AI-service intelligence collection within a centralized operational framework.
The malware uses a controller-driven architecture to coordinate scanning across large IP ranges, including cloud-provider address space, while also prioritizing targets identified through Shodan-based reconnaissance. Reported target technologies include exposed Docker and Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MCP implementations capable of command execution, as well as AI-related platforms such as Ollama, ComfyUI, Open WebUI, Langflow, Gradio, and n8n. NadMesh supports more than 20 exploitation vectors and can continue scanning or rescanning productive targets autonomously, with logic intended to reduce repeated interaction with suspected honeypots.
After compromise, NadMesh establishes persistence through SSH authorized-key backdoors, hidden binary copies, and cron-based watchdog mechanisms. It uses polymorphic build techniques, including obfuscation, packing, and randomized padding, to hinder signature-based detection and ensure deployed samples differ across infections. The botnet’s controller manages bot registration, tasking, result collection, and operator visibility through a web panel.
NadMesh places particular emphasis on harvesting high-value access material rather than merely retaining host control. Reported collection objectives include cloud credentials, environment-variable secrets, Kubernetes service account tokens, Docker configuration data, SSH session material, AI model inventories, and information about exposed or exploitable MCP services. This indicates an operational objective centered on downstream access to cloud resources, cluster privileges, and AI-related assets. The threat actor behind NadMesh is not publicly identified with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
控制端支持的利用方式,按优先级排列: ... WebLogic 反序列化RCE 中 CVE-2016-0638等 | 由于其控制端在代码中自称 n4d mesh controller ,我们将其命名为 NadMesh 。 NadMesh 并非一次性的蠕虫爆发,而是一个长期迭代、目标明确指向 AI 基础设施与 MCP 生态的自治型僵尸网络。
Older entries need their conditions checked before you panic: CVE-2022-22947 at 6.48% only bites if the Spring Cloud Gateway Actuator endpoint is enabled and exposed unsecured. | A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
...and CVE-2017-12611 at 4.15% is the Struts Freemarker tag flaw. | A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
The chart includes CVE-2026-39987, the pre-auth RCE in Marimo notebooks before 0.23.0. CISA put it on KEV in April after it was exploited within hours of disclosure. | A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
Next to it sits CVE-2026-41176, which lets an unauthenticated caller flip rc.NoAuth on rclone RC servers from 1.45.0 up to 1.73.5 that were started without HTTP auth. rclone configs are cloud credentials. | A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
This script programmatically queries the Shodan API for exposed AI and automation services, specifically profiling applications such as ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio.
The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MCP implementations capable of command execution.
NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MCP implementations capable of command execution.
Following successful exploitation, the malware establishes persistence through SSH authorized keys, hidden binaries, and scheduled cron jobs.
The system uses code obfuscation and random padding to change the malware hash dynamically. Consequently, this polymorphic approach defeats traditional signature-based detection tools.
It collects cloud credentials, Kubernetes service account tokens, Docker configuration files, environment variables, and information about deployed AI models and MCP services before reporting the data to its command-and-control server.
It collects cloud credentials, Kubernetes service account tokens, Docker configuration files, environment variables... before reporting the data to its command-and-control server.
"internal_ranges": ["10.0.0.0/8", "172.16.0.0/12"]
NadMesh uses a centralized controller to coordinate scanning across large IP ranges... The campaign also prioritizes AI-related services—including Ollama, ComfyUI, Open WebUI, Langflow, Gradio, and n8n—which are identified through Shodan searches and added to the scanning queue.
"profile": {"hostname": "prod-server-01", "os": "linux", "arch": "x86_64", "kernel": "5.10.0"
It collects cloud credentials, Kubernetes service account tokens, Docker configuration files, environment variables, and information about deployed AI models and MCP services before reporting the data to its command-and-control server.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Autonomous botnet/platform that combines scanning, exploitation, credential theft, AI-service intelligence collection, SSH backdoor deployment, and theft of tokens, environment variables, and cloud/container configurations.
Autonomous botnet/platform that performs scanning, exploitation, credential and AI-service intelligence harvesting, drops an SSH backdoor, and steals tokens and configuration data.
Go-based botnet targeting cloud and AI infrastructure. It autonomously scans networks, exploits exposed services and RCE paths, harvests cloud credentials and AI access configurations, uses polymorphic payloads, and maintains persistence via SSH public-key backdoors and cron watchdogs.
A Go-based botnet targeting exposed AI and MCP infrastructure. It uses Shodan-assisted reconnaissance, autonomous scanning, more than 20 exploitation vectors, centralized tasking via an HMAC-authenticated controller, persistence through SSH authorized keys and cron watchdogs, and harvests cloud, Kubernetes, Docker, and AI-related credentials and configuration data from compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.