hacker-news · Crawled Jul 17, 2026

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

3 IoCs 4 CVEs
Read original article ↗

AI Summary

A Go-based botnet named NadMesh, discovered in early July 2026, actively targets exposed AI and cloud services to harvest cloud credentials, Kubernetes tokens, and model access. The malware prioritizes exploitation of MCP (Model Context Protocol) services, Docker APIs, Jenkins consoles, and Redis instances, with a focus on credential theft rather than host compromise. The operator uses self-propagating scanning infrastructure, persistence mechanisms, and obfuscation to evade detection, while targeting specific ports associated with AI tools like ComfyUI, Ollama, Gradio, and n8n. Researchers observed real-time exploitation traffic, though success rates for MCP exploitation remain low compared to other vectors.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 3 extracted

Type Value Detail
IP 209[.]99[.]186[.]235 Details →
Domain cdnorigin[.]net Details →
SHA-1 31c69b3e12936abca770d430066f379ec1d997ec Details →

MITRE ATT&CK TTPs 40 techniques

T1021 Remote Services · Lateral Movement T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1220 XSL Script Processing · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1588.001 Malware · Resource Development T1659 Content Injection · Initial Access T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.004 Unix Shell · Execution T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090.001 Internal Proxy · Command And Control T1090.002 External Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1090.004 Domain Fronting · Command And Control T1110.001 Password Guessing · Credential Access T1203 Exploitation for Client Execution · Execution T1218.001 Compiled HTML File · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1498 Network Denial of Service · Impact T1498.001 Direct Network Flood · Impact T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1573.002 Asymmetric Cryptography · Command And Control T1573.003 T1573.003 T1573.004 T1573.004