New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
ID: 3189cbee-9737-51ec-a704-4c3149815ffc
STIX ID: report--3189cbee-9737-51ec-a704-4c3149815ffc
Feed Name: The Hacker News
## Executive summary NadMesh is an active Go botnet observed in July that scans for exposed AI services and admin interfaces (ComfyUI, Ollama, Gradio, n8n, Docker, Jenkins, Redis, Telnet) to harvest cloud credentials, Kubernetes service tokens, and other secrets; operators claim thousands of AWS keys and the campaign uses multiple exploit vectors, persistent multi-build agents with obfuscation, and a rescan/queueing infrastructure to prioritize targets — indicators include C2 209.99.186.235, domain cdnorigin.net, and sample SHA1 31c69b3e12936abca770d430066f379ec1d997ec.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
