NadMesh
Unknown — assessed financially motivated criminal operator · Cloud credential theft / cryptocurrency mining / botnet building
Tactics, Techniques & Procedures (TTPs)
- Automated Shodan API queries to discover internet-exposed AI service endpoints by service fingerprint and port
- Go-compiled cross-platform mesh botnet (Linux/amd64, Linux/arm64, Linux/arm) with distributed peer-to-peer C2
- Exploit modules for Ollama (CVE-2026-7482 and model upload exploitation), ComfyUI (custom node Python execution), n8n (Execute Command node), Langflow (CVE-2025-3248 unauthenticated RCE), Gradio, Open WebUI, LocalAI, AnythingLLM, Flowise
- Cloud credential harvesting: environment variables, ~/.aws/credentials, ~/.config/gcloud/, service account key files, AWS/GCP/Azure instance metadata service queries
- No human operator involvement at execution stage — fully automated discovery-to-exploitation-to-exfiltration pipeline
Known Targets
Analyst Notes
Documented by Wiz Research in July 2026 as an AI-service-targeting botnet framework with 20+ built-in exploit chains. The operator claims to have harvested 3,811+ AWS access keys from compromised AI service environments; researchers found credential batches on dark web forums consistent with this claim. The target set reflects the attack surface of the rapidly deployed self-hosted AI ecosystem: tools designed for local use, deployed on cloud infrastructure with cloud credentials in environment, without the authentication and network binding configuration required for public-facing services. NadMesh represents the transition from opportunistic targeting of individual AI services to an industrialised systematic campaign framework specifically built around this attack surface. The Bleeding Llama disclosure (CVE-2026-7482 in Ollama) notes NadMesh as already incorporating that vulnerability in its scanner.
Also Known As
MITRE ATT&CK Techniques