Thehackernews
KadNap Malware Infects 14,000+ Edge Devices for Proxy Botnet Operations
First seen 10 Mar 2026, 16:41 UTC
•



+16
•86% similarity
•66.5
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The KadNap malware has infected over 14,000 edge devices, primarily targeting ASUS routers, to create a decentralized proxy botnet. This botnet utilizes a custom version of the Kademlia Distributed Hash Table protocol, complicating efforts to identify and disrupt its command-and-control infrastructure. The malware has been active since August 2025, raising significant concerns about its potential for cybercrime activities.
ThreatCluster AI
How this analysis works
Timeline
2025-08-01
KadNap malware first detected targeting edge devices
2025-08-15
KadNap botnet reaches 1,000 infected devices
2025-12-01
KadNap botnet grows to 5,000 infected devices
2026-03-10
KadNap malware infects over 14,000 devices