NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool Access — Threadlinqs Intelligence
As of 2026-07-26, NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool Access is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1455 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-26 · 2 updates · revalidated 2× · latest source
QiAnXin XLab uncovered NadMesh, a Go-based, Garble/UPX-packed botnet with 20+ RCE vectors (Docker API, Jenkins, Redis, Kubernetes, Spring Cloud Gateway, Struts, Marimo, rclone, and more) that
NadMesh (named for a 'n4d mesh controller' string found in its source) is a continuously-iterated, Go-based botnet identified by QiAnXin's XLab team in early July 2026. Unlike commodity IoT/DDoS botnets, NadMesh is purpose-built as a credential- and intelligence-harvesting platform targeting the rapidly-expanding, often carelessly-exposed self-hosted AI tooling ecosystem: ComfyUI (port 8188), Ollama (11434), n8n (5678), Open WebUI, Langflow, and Gradio (7860). The operator maintains an autonomous scanning engine seeded with 90+ cloud-provider CIDR ranges and a 30-port probe list, and integrates Shodan queries (via an `ai_harvest.py` helper) that inject discovered AI-service IPs as priority=20 scan tasks — second only to priority=50 rescans of already-confirmed-vulnerable hosts.
Exploitation is delivered through more than 20 distinct vectors, dominated by Docker API RCE on port 2375 (30.31% of observed exploitation traffic), Jenkins script-console RCE (22.28%), weak Telnet credentials (10.36%), and Redis CONFIG SET/SAVE-based file-write RCE (8.29%), rounded out by Kubernetes pod-creation/hostPath-mount escapes, Elasticsearch scripting RCE, Spring Cloud Gateway Actuator expression injection (CVE-2022-22947), Apache Struts Freemarker RCE (CVE-2017-12611), Marimo unauthenticated terminal WebSocket RCE (CVE-2026-39987), rclone RC authentication-bypass (CVE-2026-41176), WebLogic deserialization, and code-server/Airflow/Superset/XXL-Job API abuse. A dedicated MCP JSON-RPC `execute_command` vector accounts for only 0.78% of raw traffic but is explicitly prioritized by the controller as a strategic target because it grants direct arbitrary command execution on any exposed Model Context Protocol tool server.
Once a host is compromised, the agent harvests AWS_ACCESS_KEY_ID/secret pairs and Bedrock API credentials from environment variables and `~/.aws/config`, Kubernetes ServiceAccount tokens (including cluster-admin scoped tokens), Docker daemon status and `~/.docker/config.json` credentials, arbitrary `.env` file contents, SSH session tokens, and — uniquely — an inventory of locally available AI models (e.g., installed Ollama models, configured OpenAI-compatible keys) and any MCP tools exposed by the host, each tagged with an automated exploitability assessment. The operator's own dashboard claims 3,811 unique harvested AWS keys.
Persistence is triple-redundant: SSH backdoor via `.ssh/authorized_keys` injection, dropped payload copies at `/dev/shm/.a`, `/var/tmp/.a`, and `/tmp/.a`, and cron watchdogs at `/etc/cron.d/.sys_monitor` and `/etc/cron.d/.s`. Every build is individually obfuscated with Garble (symbol/literal rewriting) and packed with UPX -9 plus random padding, producing a unique hash per binary to defeat static signature detection. The controller (available in functionally-identical Go and Python implementations) listens on ports 80/8443 behind spoofed nginx response headers, authenticates bots via HMAC-SHA256 with a ±60 second timestamp window, authenticates operators via an `X-Operator-Key` header, and protects the management panel with hourly-rotating SHA-256 session cookies. Backend state uses an in-memory hot path (sync.Map + channels + ring buffers) asynchronously flushed to PostgreSQL every 30 seconds. The operator runs supporting automation scripts — `yield_generator.py` (amplifies top-50 high-yield /16 subnets every 5 minutes), `auto_inject.sh` (rescans confirmed-dangerous IPs every 15 minutes at priority=20), `reinject.sh` (full 7-day rescan at priority=50), and `auto_blacklist.sh` (hourly honeypot detection — any target absorbing 10+ failed deployment attempts without ever returning a result is automatically blacklisted as a suspected honeypot). A canary/A/B rollout endpoint (`/api/update/canary`) had served 5,448 canary responses versus 84,024 null responses at time of analysis, and observable 'conversion funnel' statistics (success / exploit_sent / failed / intel) across the panel suggest a commercial, ROI-tr
Weaknesses (CWE)
CWE-306, CWE-15, CWE-917, CWE-94, CWE-20, CWE-287, CWE-502, CWE-284, CWE-798
Target sectors: technology, software-development, cloud-services, ai-ml-operators, managed-service-providers
Target regions: Global
Related threats
- Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host Breakout (nsenter) → Kubernetes Secret Store Dump (Sysdig TRT)
- PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh)
- Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295) Targets Managed Kubernetes Clusters
- P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month Dormancy (CVE-2022-0543, CVE-2025-11953, CVE-2025-49844)
- First AI-Agent-Driven Cloud Intrusion — Marimo CVE-2026-39987 RCE → AWS Secrets Manager → SSH Bastion → Internal PostgreSQL Exfiltration (Sysdig TRT, 2026-05-10)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2026-39987, CVE-2026-41176, CVE-2022-22947, CVE-2017-12611, CVE-2016-0638, T1595.001, T1596, T1587.001, T1588.002, T1583.004, T1190, T1133, T1078, T1059.004, T1609