NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
ID: 6141fb48-3c5b-58a5-b71b-32000cfacdf5
STIX ID: report--6141fb48-3c5b-58a5-b71b-32000cfacdf5
Feed Name: cybersecurityNews.com
NadMesh is a sophisticated Go-based botnet actively targeting exposed AI and MCP infrastructure by using a Shodan-driven reconnaissance module to prioritize live AI services (ComfyUI, Ollama, n8n, Gradio) and a large exploitation arsenal (20+ vectors) to gain persistence, harvest credentials and API tokens, and funnel intelligence to a centralized operator dashboard; the report includes technical TTPs, persistence and obfuscation methods, prioritized ports, and IOCs (C2 IP 209.99.186.235 and domain cdnorigin.net).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
