NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MCP implementations capable of command execution. The campaign also prioritizes AI-related services—including Ollama, ComfyUI, Open WebUI, Langflow, Gradio, and n8n—which are identified through Shodan searches and added to the scanning queue.
Following successful exploitation, the malware establishes persistence through SSH authorized keys, hidden binaries, and scheduled cron jobs. It collects cloud credentials, Kubernetes service account tokens, Docker configuration files, environment variables, and information about deployed AI models and MCP services before reporting the data to its command-and-control server. The controller also supports periodic rescanning of previously identified targets and includes mechanisms intended to avoid repeatedly interacting with suspected honeypots.