Published on July 19, 2026
New NadMesh Botnet Targets Exposed AI and SSH Services to Expand Global Network
Severity
Medium
Detail
Security researchers have identified a new botnet named NadMesh that actively targets exposed AI services and Secure Shell (SSH) servers to compromise internet-facing systems. According to the researchers, the botnet scans for publicly accessible services and exploits weak or exposed environments to recruit devices into its network.
The campaign has been observed targeting systems running AI-related services as well as SSH services exposed to the internet. Once compromised, infected devices become part of the NadMesh botnet and can receive commands from attacker-controlled infrastructure.
How?
The NadMesh botnet searches for publicly exposed AI services and SSH servers. After identifying vulnerable targets, it attempts to compromise them and deploy its malware. Once installed, the malware connects to a command-and-control (C2) server to receive instructions. Researchers observed that the botnet is capable of downloading additional payloads, executing commands, and maintaining communication with its C2 infrastructure to manage infected devices.
Impact
Successful compromise allows attackers to add exposed AI and SSH systems to the NadMesh botnet. Infected devices become remotely controllable through the botnet’s infrastructure and can be used as part of a larger malicious network.The campaign demonstrates that internet-facing AI services are increasingly targeted alongside traditional exposed services such as SSH.
Recommendations
Researchers advised organizations to:
- Secure AI services and avoid exposing them directly to the internet where possible.
- Restrict SSH access and enforce strong authentication mechanisms.
- Keep internet-facing systems updated with the latest security patches.
- Continuously monitor exposed services for suspicious activity and unauthorized access attempts.
Conclusion
The NadMesh campaign highlights the growing interest of threat actors in targeting internet-exposed AI services in addition to traditional SSH servers. By compromising vulnerable systems and incorporating them into a botnet, attackers continue to expand their infrastructure and increase their operational capabilities.
Source
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.htm
