NadMesh Botnet Targets AI Services and Cloud Environments
ID: 2d82bf9f-3bbd-54a3-b58a-e6db84d97c94
STIX ID: report--2d82bf9f-3bbd-54a3-b58a-e6db84d97c94
Feed Name: securityonline.info
The NadMesh botnet is an autonomous, Go-based malware campaign that scans and exploits exposed cloud and AI infrastructure (including Docker, Kubernetes, Redis, ComfyUI, Ollama, and Gradio), deploys polymorphic payloads, and harvests cloud credentials and model access tokens; researchers observed active infections and a central C2 used to direct scanning and data exfiltration, and defenders are advised to secure cloud endpoints, rotate keys, and monitor for unauthorized SSH keys and cron jobs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
