{"id":14413,"date":"2026-07-19T10:03:38","date_gmt":"2026-07-19T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/19\/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure\/"},"modified":"2026-07-19T10:03:38","modified_gmt":"2026-07-19T10:03:38","slug":"nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/19\/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure\/","title":{"rendered":"NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure"},"content":{"rendered":"<p>    NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. <\/p>\n<p class=\"wp-block-paragraph\">This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade, ROI-driven attack platform aimed squarely at Artificial Intelligence (AI) and Model Context Protocol (MCP) infrastructure. <\/p>\n<p class=\"wp-block-paragraph\">Unlike traditional worms that spread indiscriminately, NadMesh combines autonomous scanning, over 20 unique exploitation vectors, and Shodan-powered intelligence harvesting into a single closed-loop system its operator refers to as the \u201cn4d mesh controller\u201d.<\/p>\n<h2 id=\"h-nadmesh-uses-shodan-to-find-and-hijack-exposed-ai\" class=\"wp-block-heading\"><strong>NadMesh Uses Shodan to Find and Hijack Exposed AI<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The most distinctive feature of NadMesh is a dedicated reconnaissance module named <code>ai_harvest.py<\/code>. This script programmatically queries the Shodan API for exposed AI and automation services, specifically profiling applications such as ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. <\/p>\n<p class=\"wp-block-paragraph\">Once exposed services are mapped, the malware automatically injects the discovered IP addresses into its scanning queue at the highest priority tier.<\/p>\n<p class=\"wp-block-paragraph\">This methodology mirrors a broader threat trend already observed across cloud ecosystems where automated scanners sweep cloud IP ranges for unauthenticated instances vulnerable to remote code execution. <\/p>\n<p class=\"wp-block-paragraph\">By outsourcing initial reconnaissance tasks to Shodan rather than relying solely on slow, resource-heavy brute-force internet scanning, NadMesh\u2019s operators can immediately zero in on live AI deployments instead of wasting bandwidth on dead address space. <\/p>\n<p class=\"wp-block-paragraph\">Cybercriminals continuously optimize these infrastructure scanning workflows, reminiscent of multi-stage operations like the <a href=\"https:\/\/cybersecuritynews.com\/encrypthub-a-multi-stage-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">EncryptHub campaign<\/a> that systematically target internal corporate networks.<\/p>\n<p class=\"wp-block-paragraph\">Comprehensive intelligence detailing conversion funnels, binary compilation patterns, and active infection clusters can be reviewed in the comprehensive <a href=\"https:\/\/blog.xlab.qianxin.com\/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NadMesh Botnet Analysis report<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhGM1pH7kc18uJsKvmF35P-i6X4aeCBdDm6yerJBts_OLWILTShEEE8gCrzmtFGSqiAfTGL7LbHwNqdFGoj-TusFzmQI6BtaNMyw0Vcz4jR1UHd6yH-mRnFkHj0C5bE2ObFdHgCBRLeAyqv16YU3qklm3EnDx5Dg8EXbh3D2-h-kr1XanmwsV2IxKPGYnM\/s1600\/------2026-07-10-12.35.21.webp?ssl=1\" alt=\"Operator dashboard tracking active bot counts, harvested credentials, and task metrics.\"><figcaption class=\"wp-element-caption\">Operator dashboard tracking active bot counts, harvested credentials, and task metrics. (Image Source : xlab)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The botnet\u2019s operation runs through five tightly coordinated stages: intelligence gathering, centralized control, autonomous task supply, polymorphic binary construction, and active delivery. The central controller listens on ports 80 and 8443, utilizing HMAC-authenticated beacons to manage its fleet of compromised bots. <\/p>\n<p class=\"wp-block-paragraph\">It also exposes an advanced web management panel equipped with conversion-funnel analytics, automated canary updates, and real-time operational visibility\u2014features far more typical of enterprise commercial software than traditional malicious code. <\/p>\n<p class=\"wp-block-paragraph\">Once an endpoint is infected, bot agents establish redundant persistence layers using SSH authorized-key backdoors, multiple hidden binary duplicates, and cron-based watchdog processes to ensure that removing any single artifact fails to clear the infection.<\/p>\n<p class=\"wp-block-paragraph\">The malware actively scans 30 distinct ports covering enterprise web services, Kubernetes clusters, database management systems, container APIs, and internal monitoring tools. AI service ports receive strict prioritization during these sweeps, particularly:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Port 8188:<\/strong> ComfyUI<\/li>\n<li>\n<strong>Port 11434:<\/strong> Ollama<\/li>\n<li>\n<strong>Port 5678:<\/strong> n8n<\/li>\n<li>\n<strong>Port 7860:<\/strong> Gradio<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Its exploitation arsenal spans over 20 vectors, targeting MCP JSON-RPC tool calls, malicious Kubernetes pod creation, Docker API container escapes, unauthenticated Redis instances, Elasticsearch remote code execution (RCE), Jenkins Script Console components, and legacy flaws like WebLogic deserialization.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi8l5NGu3g0O1Z_1xvuTtL4LZDTb0WbeBk74G_pJ-bStLAreBrn-qMOQBg1CtzHciJp5ylKPGyI41HTq-UY2_ngLCeoWVL1Q_Q3C9kBOxfudR2OsOravj-r4c7hjPMuMnplDChtEfDc7ZEOedbj_dj4g-LP-Zgy-s3AdKcpaWftkCnqxWikVD-bSGStKQU\/s1600\/mesh-vul.webp?ssl=1\" alt=\"Chart capturing the percentage distribution of different RCE exploit targets\"><figcaption class=\"wp-element-caption\">Chart capturing the percentage distribution of different RCE exploit targets (Image Source : xlab)<\/figcaption><\/figure>\n<\/div>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td><strong>Target Attack Surface<\/strong><\/td>\n<td><strong>Primary Exploitation Vector<\/strong><\/td>\n<td><strong>Implicated Severity Risk<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>MCP Servers<\/strong><\/td>\n<td>\n<code>JSON-RPC tools\/call<\/code> -&gt; <code>execute_command<\/code> execution loops<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td><strong>Kubernetes<\/strong><\/td>\n<td>Malicious pod creation paired with <code>hostPath<\/code> mount overrides<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td><strong>Docker API<\/strong><\/td>\n<td>Privileged container creation to facilitate escape sequences<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td><strong>Redis Infrastructure<\/strong><\/td>\n<td>Unauthenticated <code>CONFIG SET<\/code> file write operations<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td><strong>AI Services<\/strong><\/td>\n<td>Shodan-sourced prioritization of ComfyUI, Ollama, n8n, and Gradio<\/td>\n<td>High<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Beyond establishing an initial access foothold, compromised hosts are thoroughly mined for high-value architectural data. <\/p>\n<p class=\"wp-block-paragraph\">The malware actively extracts AWS access keys, Amazon Bedrock credentials, Kubernetes <code>ServiceAccount<\/code> tokens with cluster-admin scopes, local Docker configurations, and comprehensive inventories of locally hosted AI models (including Llama2, Mistral, and active GPT-4 API tokens). It also harvests access configurations for exploitable internal MCP tools like <code>execute_sql<\/code> and <code>execute_shell<\/code>. <\/p>\n<p class=\"wp-block-paragraph\">All recovered data is funneled back to a central dashboard that tracks aggregate certificate counts, active MCP vulnerabilities, and escapable Docker hosts\u2014threat intelligence that proves far more lucrative to the operator than the compromised compute resources themselves.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgd0bfSJkejtLDPbhh7a-cbWLT4ztIJaVN4hyHa_geAyZOX7nDid4HCHLYnmRZKl-WOvmGWQcaPuYzNbsqj03yv5e5DJxyJqvyqX9k1br_zHcOE2Itf6c3ou6DtYbpn-02IS-LQfBmCYeYABvdYJpr8PP0PGAkqUQDRo9Q-Av0c1m6I9FLE2CIc33ezKqs\/s1600\/Overall%2520architecture.webp?ssl=1\" alt=\"Architecture schema mapping\"><figcaption class=\"wp-element-caption\">Architecture schema mapping (Image Source : xlab)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">To evade signature-based detection mechanisms, NadMesh applies Garble obfuscation and UPX compression, ensuring that every dynamically deployed binary carries a completely unique cryptographic hash. <\/p>\n<p class=\"wp-block-paragraph\">Furthermore, it features an automated honeypot-avoidance mechanism that blacklists any IP address that fails to yield successful infection results after ten consecutive deployment attempts. <\/p>\n<p class=\"wp-block-paragraph\">Administrators running active machine learning pipelines must continually deploy modern <a href=\"https:\/\/cybersecuritynews.com\/cyber-attack-simulation-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyber attack simulation tools<\/a> to evaluate their models\u2019 exposure to these automated architectural pivots.<\/p>\n<h3 id=\"h-indicators-of-compromise-iocs\" class=\"wp-block-heading\"><strong>Indicators of Compromise (IOCs)<\/strong><\/h3>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Command and Control (C2) IP Node:<\/strong> <code>209.99.186.235<\/code>\n<\/li>\n<li>\n<strong>C2 Content Delivery Network Domain:<\/strong> <code>cdnorigin.net<\/code>\n<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\u00a0Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate ANY.RUN With Your SOC\u00a0<\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Now<\/a><\/strong>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/nadmesh-uses-shodan\/\">NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kavichselvan<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/nadmesh-uses-shodan\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,1636,63],"tags":[130],"class_list":["post-14413","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-attack-news","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14413"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14413"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14413\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}