← Back to Daily Briefing

NadMesh is a Go-based botnet targeting AI and Model Context Protocol (MCP) infrastructure via Shodan-driven reconnaissance. The malware employs over 20 unique Remote Code Execution (RCE) vectors to compromise exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The primary payload objective is the exfiltration of high-value AWS access keys and Kubernetes (K8s) service account tokens to facilitate cloud environment hijacking and lateral movement. Threat actors have utilized an operator dashboard to manage 3,811 unique stolen AWS credentials, leveraging the rapid, often insecure deployment of AI/ML software stacks.

  • Malware Profile and Reconnaissance
    • Go-based architecture providing high portability and concurrency for large-scale automated operations.
    • Integrated reconnaissance loop utilizing Shodan to identify internet-facing AI/MCP service endpoints.
    • Exploits the "fast deployment, late firewalling" pattern prevalent in modern DevOps and AI research environments.
  • Technical Attack Mechanics: RCE Exploitation
    • Deployment of 20+ distinct Remote Code Execution (RCE) vectors specifically tailored for AI-centric software.
    • Targeted exploitation of popular orchestration tools and local model runners, including ComfyUI, Ollama, and n8n.
    • Compromise of web-based interfaces and AI workflow builders such as Open WebUI, Langflow, and Gradio.
  • Impact Analysis: Cloud Credential Harvesting
    • Systematic exfiltration of high-value AWS Access Keys and Secret Keys.
    • Theft of Kubernetes (K8s) service account tokens to enable lateral movement within containerized clusters.
    • Reported scale includes the management of 3,811 unique harvested AWS credentials via a dedicated operator dashboard.
  • Defensive Recommendations: Hardening AI Infrastructure
    • Eliminate public-facing exposure of AI management interfaces, orchestration tools, and local model runners.
    • Enforce strict Principle of Least Privilege (PoLP) for all AWS IAM roles and Kubernetes identities.
    • Implement robust egress filtering and monitoring for unauthorized API calls and anomalous outbound traffic from AI environments.

Related posts

  1. gbhackers.com — New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
  2. serisec.com — New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
  3. serisec.com — NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
  4. arXiv (Computer Science - Cryptography and Security) — SoK: DARPA's AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned
  5. unit42.paloaltonetworks.com — The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
  6. news.ycombinator.com — Cloudflare OS: an open platform for agents, apps, and work
  7. opensourceforu.com — Bitcoin Red Team To Open Source AI Security Harness After Major Audit
  8. gbhackers.com — Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
  9. arXiv (Computer Science - Cryptography and Security) — One Word at a Time: Incremental Completion Decomposition Breaks LLM Safety
  10. malware-log.hatenablog.com — Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet
  11. cyberscoop.com — AI’s ‘middle class’ has gotten dramatically better at hacking
  12. thenewstack.io — DeepSeek open sources an agent harness where everything is a plugin
  13. DEV Community — DeepSeek Harness: What "Everything is a Plugin" Actually Means for Agent Frameworks
  14. opensourceforu.com — Google Open-Sources HEIR for Encrypted AI
  15. helpnetsecurity.com — Google’s open-source HEIR lets AI work with data it can’t see
  16. News4Hackers — Google’s Open-Source HEIR: AI Power with Privacy-Preserving Data Handling
  17. opensourceforu.com — Roblox Open-Sources AI Safety Models
  18. SecurityWeek — Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
  19. cybersecurity.pk — New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
  20. news.ycombinator.com — VulnHunter: Capital One's agentic AI code security tool
  21. feeds.feedburner.com — New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
  22. Cyberpress
  23. Cypro
  24. Buttondown
  25. Thedailytechfeed
  26. Pulse2
  27. Aiagentsdirectory
  28. Daily
  29. Byteiota
  30. Reddit
  31. Venturebeat
  32. Portalerp
  33. Youtube
  34. Arpa-h
  35. Darkreading
  36. Darpa
  37. Openssf
  38. Usenix
  39. Researchgate
  40. Aicyberchallenge
  41. Gatech
  42. Youtube
  43. Dnaihao
  44. Researchgate
  45. Openresearch
  46. Colm

LINK COPIED TO CLIPBOARD