Drooid Logo
Back to story perspectives

Full Breakdown

KadNap Malware: A Takedown-Resistant Botnet Targeting Asus Routers

3/13/2026, 7:12:10 AM

Overview of the KadNap Botnet

Researchers from Lumen's Black Lotus Labs have identified a significant cybersecurity threat in the form of a botnet named KadNap, which has infected over 14,000 routers and network devices, predominantly those manufactured by Asus. This malware exploits unpatched vulnerabilities to create a proxy network that facilitates cybercriminal activities. The botnet's design employs a sophisticated peer-to-peer architecture based on the Kademlia Distributed Hash Table (DHT) protocol, allowing it to evade traditional detection and takedown efforts.

Key Characteristics of KadNap

KadNap's unique structure utilizes a custom version of the Kademlia DHT, which enables infected devices to communicate without revealing the IP addresses of command-and-control servers. This decentralized approach not only conceals the botnet's infrastructure but also makes it resilient against law enforcement interventions. The botnet's operators have reportedly increased the number of infected devices from 10,000 in August 2025 to an average of 14,000 per day, with approximately 60% of these devices located in the United States. Other affected regions include Taiwan, Hong Kong, Russia, the United Kingdom, Australia, Brazil, France, Italy, and Spain.

The Role of the Doppelgänger Proxy Network

KadNap is linked to a proxy service known as Doppelgänger, which allows users to leverage the hijacked devices for various malicious purposes, including brute-force attacks and targeted exploitation campaigns. The malware's ability to blend in with legitimate peer-to-peer traffic complicates efforts to disrupt its operations, as it can hide within the noise of regular network activity.

Official Statements & Responses

Lumen has stated that its customers have been protected from KadNap attacks since August 2025. The company plans to publicly share indicators of compromise (IoC) to assist other organizations in safeguarding their networks. Security professionals are advised to monitor for suspicious logins and weak credentials, even from seemingly safe IP addresses, and to ensure that routers are regularly updated and secured.

Criticism & Opposition

Despite the alarming nature of the KadNap botnet, there has been limited response from Asus regarding the issue. The lack of communication from the manufacturer raises concerns about the effectiveness of their security measures and the potential vulnerability of their devices.

Conflicting Reports & Gaps

While the majority of infected devices are reported to be in the United States, there are discrepancies regarding the exact distribution of infections across other countries. Some sources indicate a broader spread in Europe and Australia, while others focus primarily on the U.S. This inconsistency highlights the need for further investigation into the global impact of the KadNap malware.

Verbatim Quotes

  • “The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control,” — Chris Formosa, Researcher at Lumen's Black Lotus Labs
  • “The innovative use of the DHT protocol allows the malware to establish robust communication channels that are difficult to disrupt, by hiding in the noise of legitimate peer-to-peer traffic,” — Black Lotus Labs Report

As the KadNap botnet continues to pose a significant threat, ongoing vigilance and proactive security measures are essential for organizations and individuals alike.