A newly discovered Go-based botnet dubbed NadMesh is hunting exposed AI services and Model Context Protocol (MCP) deployments to siphon AWS keys, Kubernetes tokens, Docker configurations, and model access from compromised hosts, according to threat researchers who published their findings in mid-July 2026.
July 2026 · Threat Intelligence
NadMesh: The First Botnet Built for the Self-Hosted AI Era
A Go-based, "product-grade" botnet is actively hunting exposed AI services and Model Context Protocol servers — siphoning AWS keys, Kubernetes tokens, and model access to turn inference servers into a foothold for deeper cloud compromise.
20+
Remote code execution vectors bundled in the toolkit
30+
Ports probed during scanning sweeps
90+
Cloud-provider CIDR ranges targeted
3×
Redundant persistence mechanisms per host
Triple-Redundant Persistence
Three independent footholds must all be cleared — killing one relaunches the others.
1
SSH backdoor
Public-key implant
2
Staged copies
/dev/shm · /var/tmp · /tmp
3
Cron watchdogs
Relaunch if killed
Attack Lifecycle on Each Compromised Host
Discover
Shodan API prioritizes ComfyUI, Ollama, n8n, MCP servers
→
Exploit
20+ RCE vectors: MCP, K8s, Docker, Redis
→
Persist
Triple foothold + hash-unique binaries
→
Spread & Steal
P2P lateral movement; exfil cloud credentials
Why It's Different
Not another DDoS botnet — an "industrial-grade," ROI-focused platform built to monetize stolen cloud credentials and AI execution rights.
Automated amplification loops
Honeypot evasion & statistical dashboards
Garble + UPX-9 obfuscation, unique hashes
The Takeaway for AI Teams
Self-hosted stacks — ComfyUI, Ollama, n8n, Gradio, and MCP servers — left reachable on the public internet, plus the cloud credentials they can access, are now being actively hunted. No victim counts have been released, but the target is clear.
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…