Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [botnet, malware, stealer, ai-security] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true

NadMesh Botnet

NadMesh is a Go-based botnet discovered by QiAnXin's XLab that scans Shodan for exposed AI services to harvest cloud credentials and Kubernetes tokens.

Discovery

  • Discovered by: QiAnXin XLab (July 2026)
  • Language: Go (Golang)
  • Targets: Exposed AI services on Shodan (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) (raw/digests/Cyber-Digest-2026-07-18)

Capabilities

  • Scans Shodan for internet-exposed AI/ML service interfaces
  • Harvests AWS cloud keys, Kubernetes tokens, and AI model credentials
  • Stolen credentials span DeepSeek, GLM, and Kimi model inventories

Impact

According to the operator's dashboard:

Metric Value
Unique AWS keys harvested 3,811
Total deploys 17,700

Australian Significance

As AI/ML services become more widely deployed across Australian organisations (government, research, and private sector), unhardened AI service interfaces โ€” particularly ComfyUI, Ollama, and Langflow โ€” represent an attractive target for botnet operators. Organisations running these services should ensure they are not exposed to the public internet. Au Impact

Related Pages