N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
released on 2026-08-20 @ 05:08:38 PM
N4D Mesh Controller is an active Linux malware campaign exploiting exposed Model Context Protocol (MCP) servers and various internet-facing services for credential theft, lateral movement, and command and control. First documented in June 2026, recent analysis reveals evolved tactics including a new loader-to-agent chain, rotated infrastructure using IP 209.99.186.235, and an agent labeled "33.8-go-titan" that enumerates MCP tools and executes commands. The campaign automates discovery and abuse of dangerous MCP capabilities, particularly command execution tools, without requiring traditional vulnerabilities. The agent establishes persistence through multiple mechanisms including cron entries, systemd units, SSH keys, and watchdog scripts, while scanning for additional targets across databases, container platforms, AI infrastructure including Ray Dashboard and LightLLM, and cloud services. Secondary access is maintained through Cloudflare Quick Tunnels.