Bleeping Computer reports that a new botnet malware named KadNap is actively compromising ASUS routers and other edge networking devices, repurposing them as proxies for malicious activities. The botnet has rapidly expanded since August 2025, infecting approximately 14,000 devices, according to Lumen Technologies' Black Lotus Lab.KadNap operates as a peer-to-peer network, utilizing a custom version of the Kademlia Distributed Hash Table (DHT) protocol to communicate with its command-and-control (C2) infrastructure. This decentralized approach makes it challenging to identify and disrupt the C2 servers. Researchers at Black Lotus Labs noted that nearly half of the KadNap network is linked to ASUS-based bots, with the remainder communicating with separate control servers. The majority of infected devices are located in the United States, followed by Taiwan, Hong Kong, and Russia. The infection process involves downloading a malicious script that establishes persistence and installs an ELF binary, which then contacts NTP servers and uses the modified Kademlia DHT to locate botnet nodes and C2 servers.The KadNap botnet is associated with the Doppelganger proxy service, which sells access to infected devices for malicious traffic routing, pseudonymization, and evading blocklists. These proxies are often used for DDoS attacks, credential stuffing, and brute-force attacks. While Lumen Technologies has taken steps to block traffic to the botnet's control infrastructure on its network, broader disruption requires wider adoption of indicators of compromise.Source: Bleeping Computer
IoT, Network Security, Threat Intelligence, Malware
KadNap botnet targets ASUS routers, leverages custom Kademlia protocol

An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


