Skip to content
KadNap Malware Infects 14,000+ Edge Devices for Proxy Botnet Operations

KadNap Malware Infects 14,000+ Edge Devices for Proxy Botnet Operations

First seen 10 Mar 2026, 16:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 24, 2026 at 12:43 UTC

The KadNap malware has infected over 14,000 edge devices, primarily targeting ASUS routers, to create a decentralized proxy botnet. This botnet utilizes a custom version of the Kademlia Distributed Hash Table protocol, complicating efforts to identify and disrupt its command-and-control infrastructure. The malware has been active since August 2025, raising significant concerns about its potential for cybercrime activities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

Timeline

2025-08-01
KadNap malware first detected targeting edge devices
2025-08-15
KadNap botnet reaches 1,000 infected devices
2025-12-01
KadNap botnet grows to 5,000 infected devices
2026-03-10
KadNap malware infects over 14,000 devices

More articles in this cluster (22)

Following this threat?

Track KadNap in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed