KadNap Malware Infects 14,000+ Edge Devices for Proxy Botnet Operations

KadNap Malware Infects 14,000+ Edge Devices for Proxy Botnet Operations

First seen 10 Mar 2026, 16:41 UTC BleepingcomputerThehackernewsSecurityaffairs.CoTechnaduScworld+16 86% similarity 66.5

Article Content

Browse articles
ThreatCluster

The KadNap malware has infected over 14,000 edge devices, primarily targeting ASUS routers, to create a decentralized proxy botnet. This botnet utilizes a custom version of the Kademlia Distributed Hash Table protocol, complicating efforts to identify and disrupt its command-and-control infrastructure. The malware has been active since August 2025, raising significant concerns about its potential for cybercrime activities.

ThreatCluster AI How this analysis works

Timeline

2025-08-01
KadNap malware first detected targeting edge devices
2025-08-15
KadNap botnet reaches 1,000 infected devices
2025-12-01
KadNap botnet grows to 5,000 infected devices
2026-03-10
KadNap malware infects over 14,000 devices

Community

Browse all →

Tracked Entities in This Story