New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network
ID: 0a22e034-bc71-51fc-90c9-05141c8d2605
STIX ID: report--0a22e034-bc71-51fc-90c9-05141c8d2605
Feed Name: Bleeping Computer
A newly discovered botnet named KadNap is compromising ASUS routers and other edge devices to build a peer-to-peer proxy network of roughly 14,000 infected hosts using a custom Kademlia-based DHT for C2, enabling resale of access via the Doppelganger proxy service for activities like DDoS and credential stuffing; researchers at Black Lotus Labs identified geographic distribution (60% US), persistence and evasion techniques, and implementation flaws that aided tracking, and Lumen has blocked related traffic on its network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
