1 of 1
Story summary
- KadNap, a botnet identified by Lumen's Black Lotus Labs, has infected over 14,000 routers, mainly Asus devices, via unpatched vulnerabilities.
- The botnet uses a custom Kademlia Distributed Hash Table protocol to conceal its command-and-control servers.
- About 60% of infected devices are in the United States, with others in Taiwan, Hong Kong, and Europe.
- KadNap provides a proxy service called Doppelgänger that facilitates criminal activities.
