logo

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

ID: 6141fb48-3c5b-58a5-b71b-32000cfacdf5

STIX ID: report--6141fb48-3c5b-58a5-b71b-32000cfacdf5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

Author: Kavichselvan

...
...

NadMesh is a sophisticated Go-based botnet actively targeting exposed AI and MCP infrastructure by using a Shodan-driven reconnaissance module to prioritize live AI services (ComfyUI, Ollama, n8n, Gradio) and a large exploitation arsenal (20+ vectors) to gain persistence, harvest credentials and API tokens, and funnel intelligence to a centralized operator dashboard; the report includes technical TTPs, persistence and obfuscation methods, prioritized ports, and IOCs (C2 IP 209.99.186.235 and domain cdnorigin.net).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.