type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [botnet, malware, stealer, ai-security] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true
NadMesh Botnet
NadMesh is a Go-based botnet discovered by QiAnXin's XLab that scans Shodan for exposed AI services to harvest cloud credentials and Kubernetes tokens.
Discovery
- Discovered by: QiAnXin XLab (July 2026)
- Language: Go (Golang)
- Targets: Exposed AI services on Shodan (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) (raw/digests/Cyber-Digest-2026-07-18)
Capabilities
- Scans Shodan for internet-exposed AI/ML service interfaces
- Harvests AWS cloud keys, Kubernetes tokens, and AI model credentials
- Stolen credentials span DeepSeek, GLM, and Kimi model inventories
Impact
According to the operator's dashboard:
| Metric | Value |
|---|---|
| Unique AWS keys harvested | 3,811 |
| Total deploys | 17,700 |
Australian Significance
As AI/ML services become more widely deployed across Australian organisations (government, research, and private sector), unhardened AI service interfaces โ particularly ComfyUI, Ollama, and Langflow โ represent an attractive target for botnet operators. Organisations running these services should ensure they are not exposed to the public internet. Au Impact
Related Pages
- Lurking Lizard โ Residential proxy botnet (similar C2 scale)
- Modbeacon Rat โ Rust-based RAT with encrypted C2
- Redwing Maas โ Malware-as-a-Service model (different vector)