NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
A new Go-based botnet named NadMesh is actively scanning for misconfigured AI services to steal AWS keys and Kubernetes tokens. Security researchers warn that popular machine learning tools are being targeted due to weak access controls.
TL;DR
- New Go botnet 'NadMesh' discovered targeting exposed AI services.
- Over 3,800 AWS keys reportedly harvested via operator dashboard.
- Targets include ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio.
- Leverages Shodan to find publicly accessible instances.
- Highlights growing risk of credential theft in AI development environments.
In early July, security analysts identified a newly emerged botnet called NadMesh, written in Go, that specifically targets exposed artificial intelligence services. The botnet scans for misconfigured instances of commonly used AI tools such as ComfyUI, Ollama, and Gradio using Shodan, aiming to extract sensitive cloud credentials.
According to reports, the threat actor behind NadMesh has already claimed to have harvested over 3,811 unique AWS keys through its automated reconnaissance and exploitation pipeline. These tools are often rapidly deployed by development teams without proper network segmentation or authentication safeguards, making them prime targets for opportunistic attackers.
How NadMesh Operates
- Uses Shodan to identify publicly exposed AI service endpoints.
- Focuses on open-source tools including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio.
- Scans target systems for improperly secured API interfaces and configuration files.
- Extracts cloud credentials such as AWS keys and Kubernetes tokens from vulnerable installations.
Implications for Enterprise Security Teams
- Highlights the need for secure deployment practices around AI/ML tooling.
- Emphasizes importance of continuous asset discovery and exposure monitoring.
- Reinforces risks associated with developer-first tools lacking built-in security controls.
- Suggests proactive patching and access restriction policies for internal AI platforms.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.