logo

Silence of the Hops: The KadNap Botnet Conscripts 14,000 Routers

ID: e5d3a37a-87b7-54a0-b7af-5132affc49c0

STIX ID: report--e5d3a37a-87b7-54a0-b7af-5132affc49c0

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Black Lotus Labs disclosed a sophisticated botnet named "KadNap" that has infected over 14,000 devices (primarily Asus routers) to form a decentralized proxy network. KadNap uses a custom Kademlia-based P2P DHT to hide its infrastructure and evade takedown, includes persistence via an hourly cron job (aic.sh), and its compromised routers are marketed through a dark-web proxy service called "Doppelgänger"; Lumen published IoCs and recommended mitigations (firmware updates, change default credentials, monitor cron jobs, replace EOL routers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.