Monday, September 7, 2026

New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure

NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform.

In early July 2026, researchers identified NadMesh as a high‑volume Go-written botnet that was aggressively deploying bot agents across internet‑facing cloud and AI services.

The malware brands its control layer as “n4d mesh controller” in source artifacts, leading investigators to name the family NadMesh and classify it as an AI/MCP‑centric botnet rather than a generic DDoS crew.

NadMesh’s strategic objective is clear: capture AI infrastructure, compromise MCP ecosystems, and monetize cloud credentials and execution rights, aligning with recent trends in AI‑centric botnet operations and MCP tool‑poisoning attacks.

NadMesh ships an embedded autonomous scanner preloaded with address ranges from more than 90 cloud service providers, allowing continuous, unattended expansion into hyperscaler and niche cloud footprints.

The botnet’s port set spans 30 services, including web management, Kubernetes (API, kubelet, etcd), Docker APIs, Redis, Elasticsearch, SSH/Telnet, and AI frontends such as ComfyUI, Ollama, n8n, and Gradio, with AI services explicitly marked as highest‑priority targets.

On top of this coverage, the controller exposes over 20 RCE vectors, ranging from MCP JSON‑RPC command execution and Kubernetes pod escapes to Docker container abuse, Redis persistence, Elasticsearch script RCE, and classic middleware flaws such as WebLogic deserialization, Jenkins script consoles, and dashboard frameworks like Airflow and Superset.

NadMesh’s kill chain is implemented as a closed‑loop platform anchored on the attacker’s VPS, structured into five stages: intelligence, control, supply, construction, and delivery.

Intelligence collection is delegated to an AI‑focused harvester that uses the Shodan API to enumerate endpoints for ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio, injecting them into the scanning queue at the highest priority and explicitly signaling intent against AI infrastructure.

XLab Researchers observed in July 2026, shows a rapidly evolving campaign focused on cloud AI stacks, MCP tooling, and exposed orchestration services rather than traditional consumer IoT.

The Go‑based controller (controller_go.go) listens on ports 80/8443, registers bots, pushes CIDR+port task bundles, ingests exploit and credential telemetry, and exposes a full web panel at /panel with conversion funnels, deployment statistics, and operational health views designed for continuous commercial operation.


 The distribution of NadMesh exploits (Source : XLab).
 The distribution of NadMesh exploits (Source : XLab).

NadMesh’s supply side is fully automated via a quartet of scripts that amplify high‑yield segments, continuously reinject “dangerous” IPs, rescan proven exploitable hosts, and maintain an auto‑blacklist of suspected honeypots.

New NadMesh Botnet

The feedback loop is explicit: segments producing successful deployments are magnified through task injection, while IPs with repeated non‑productive deploys are flagged as research infrastructure and suppressed, demonstrating operator awareness of security monitoring and sandboxes.

Concurrently, a polymorphic build pipeline (build_agent.sh) leverages Garble obfuscation, UPX‑9 compression, and random padding to emit agents with unique hashes, hindering simple signature‑based detection across Linux fleets and cloud nodes.

On victim hosts, NadMesh agents establish “double protection” persistence with three coordinated mechanisms: SSH public‑key backdoor injection, multi‑path disk‑backed loaders, and Cron‑based watchdog tasks that revive the bot if any single artifact is removed.

The agents perform port 30 reconnaissance, banner‑based service identification, RCE delivery, internal network scanning, credential capture, and P2P beaconing across the local segment, enabling lateral diffusion without centralized tasking.

Reporting structures highlight the botnet’s true objective: cloud access keys, Kubernetes service accounts with cluster‑admin privileges, MCP tools capable of arbitrary SQL or shell execution.

AI model endpoints bound to high‑value providers such as OpenAI and Bedrock, mapping directly onto emerging MCP poisoning and AI supply‑chain attack surfaces.

Intelligence panel display  (Source : XLab).
Intelligence panel display  (Source : XLab).

NadMesh lands at a moment when MCP command‑injection and tool‑poisoning vulnerabilities are being actively documented, including advisories detailing how compromised MCP servers can be turned into universal agent backdoors.

By chaining JSON‑RPC command execution against misconfigured MCP instances with broad botnet reach and automated credential harvesting.

NadMesh turns AI orchestration stacks into both victims and amplifiers, echoing prior research showing AI infrastructure hijacking itself via autonomous exploitation.

For operators of AI platforms, MCP gateways, and cloud‑native stacks, NadMesh should be treated as a long‑term evolutionary malware family with clear ROI‑driven design, not a short‑lived worm outbreak, and prioritized in both patching and detection strategies.

𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Best in 2026? Compare costs, Automation, and response: Download Free Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands

A newly identified Chromium-based post-exploitation toolkit named PEEP can...

Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers

Threat actors are actively exploiting critical vulnerabilities in MikroTik...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Related Articles

Recent News