logo

NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure (Campaign)

ID: 88d21ee4-9a67-5e52-a43d-14ef630cd65c

STIX ID: report--88d21ee4-9a67-5e52-a43d-14ef630cd65c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-26

Author: [email protected] (Wiz Threat Research)

...
...

NadMesh is a centralized, large-scale malware campaign that scans and exploits exposed infrastructure and AI-related services discovered via Shodan using over 20 attack vectors. It establishes persistence (SSH keys, hidden binaries, cron jobs), collects cloud credentials, Kubernetes service account tokens, Docker configuration and environment data, inventories deployed AI models and MCP services, and exfiltrates the information to a command-and-control server while supporting periodic rescanning and basic honeypot avoidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.