NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure (Campaign)
ID: 88d21ee4-9a67-5e52-a43d-14ef630cd65c
STIX ID: report--88d21ee4-9a67-5e52-a43d-14ef630cd65c
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-07-17
Date Updated: 2026-07-26
Author: [email protected] (Wiz Threat Research)
NadMesh is a centralized, large-scale malware campaign that scans and exploits exposed infrastructure and AI-related services discovered via Shodan using over 20 attack vectors. It establishes persistence (SSH keys, hidden binaries, cron jobs), collects cloud credentials, Kubernetes service account tokens, Docker configuration and environment data, inventories deployed AI models and MCP services, and exfiltrates the information to a command-and-control server while supporting periodic rescanning and basic honeypot avoidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
