logo

NadMesh Botnet Targets AI Services and Cloud Environments

ID: 2d82bf9f-3bbd-54a3-b58a-e6db84d97c94

STIX ID: report--2d82bf9f-3bbd-54a3-b58a-e6db84d97c94

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

The NadMesh botnet is an autonomous, Go-based malware campaign that scans and exploits exposed cloud and AI infrastructure (including Docker, Kubernetes, Redis, ComfyUI, Ollama, and Gradio), deploys polymorphic payloads, and harvests cloud credentials and model access tokens; researchers observed active infections and a central C2 used to direct scanning and data exfiltration, and defenders are advised to secure cloud endpoints, rotate keys, and monitor for unauthorized SSH keys and cron jobs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.