Skip to content

Go-based NadMesh Botnet Harvests AWS Keys from Exposed AI Services

Bottom line: NadMesh automates the discovery and exploitation of unfirewalled AI services to gain access to cloud accounts and Kubernetes control planes.

A botnet written in Go named NadMesh specifically targets exposed AI applications to steal cloud authentication credentials. The operators’ dashboard already logs 3,811 harvested AWS keys.

The NadMesh botnet was discovered in early July and systematically targets unprotected instances of popular AI frameworks. The system uses Shodan harvesting to continuously scan for open services such as ComfyUI, Ollama, n8n, Open WebUI, Langflow and Gradio – all applications for image generation, local model execution and workflow automation that teams frequently deploy quickly without implementing adequate network access controls.

The danger lies in the combination of visibility and execution capability: these services have access to cloud provider credentials and Kubernetes orchestration tokens that administrators often store for automation or model orchestration. A compromised service becomes a bridge into the company’s cloud infrastructure and container orchestration.

For security professionals, this is a twofold problem: first, shadow AI – internally deployed tools outside formalized IT processes – is encouraged by the broad availability of these frameworks. Second, this requires that network segmentation and secrets management be considered from the outset – not as an afterthought.


Source: thehackernews.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: