14,000 Asus routers infected by takedown-resistant KadNap malware

Researchers at Black Lotus Labs have identified a botnet infecting around 14,000 routers daily, mostly Asus models in the US, using advanced peer-to-peer technology to evade detection. The malware, known as KadNap, turns these devices into proxies for cybercrime activities. Infected users are advised to factory reset their routers and apply firmware updates to remove the threat.

The KadNap botnet, discovered by Black Lotus Labs in August, has grown to infect an average of 14,000 routers and network devices per day as of March 2026, up from 10,000 infections at the time of initial detection. The majority of compromised devices are Asus routers, primarily located in the US, with smaller clusters in Taiwan, Hong Kong, and Russia. According to Chris Formosa, a researcher at Lumen’s Black Lotus Labs, the malware exploits unpatched vulnerabilities in these devices, without relying on zero-day exploits.

What sets KadNap apart is its use of a peer-to-peer network structure based on Kademlia, a distributed hash table (DHT) system originally popularized in technologies like BitTorrent. This design decentralizes control, concealing command-and-control server IP addresses and making the botnet highly resistant to traditional takedown methods. "The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control," Formosa and fellow researcher Steve Rudd wrote. "Their intention is clear: avoid detection and make it difficult for defenders to protect against."

In operation, KadNap functions by having nodes query others using a passphrase to locate control infrastructure, eventually receiving files with command-and-control addresses. The infected devices serve as proxies for Doppelganger, a fee-based service that routes customer traffic through residential internet connections to enable anonymous access to restricted sites.

Black Lotus Labs has developed methods to block traffic to the botnet's control infrastructure and is sharing indicators of compromise, such as specific IP addresses and file hashes, through public feeds. Users suspecting infection can check device logs against these indicators. To disinfect, owners must perform a factory reset—restarting alone is insufficient, as the malware persists via a shell script—and ensure firmware is updated, passwords are strong, and remote access is disabled when unnecessary.

ተያያዥ ጽሁፎች

The FBI, BND and BfV warn of attacks by Russian state hackers on TP-Link routers and WLAN extenders. The Fancy Bear group has infiltrated thousands of devices worldwide to steal sensitive data. In Germany, 30 affected devices have already been detected.

በAI የተዘገበ

Dutch authorities have taken down a botnet made up of 17 million compromised devices. They seized 200 servers that powered the network.

A newly discovered flaw in Trend Micro's Apex One allows hackers to inject malicious code. The zero-day vulnerability is being actively exploited.

በAI የተዘገበ

One week after the FCC banned sales of new foreign-made Wi-Fi routers over national security risks, new details emerge on implicated cyberattacks and growing criticism of the broad policy's effectiveness.

ይህ ድረ-ገጽ ኩኪዎችን ይጠቀማል

የእኛን ጣቢያ ለማሻሻል ለትንታኔ ኩኪዎችን እንጠቀማለን። የእኛን የሚስጥር ፖሊሲ አንብቡ የሚስጥር ፖሊሲ ለተጨማሪ መረጃ።
ውድቅ አድርግ