Researchers at Lumen Black Lotus Labs reported a new botnet malware, KadNap, that compromises ASUS routers and other edge networking devices to convert them into residential-style proxies used to relay malicious traffic. First observed in the wild in August 2025, the botnet has grown to 14,000+ infected devices, with roughly 60% of victims located in the United States and additional concentrations in Taiwan, Hong Kong, and Russia, plus smaller numbers across multiple other countries.
KadNap is designed for resilience and evasion by using a custom Kademlia-based Distributed Hash Table (DHT) to obscure and decentralize command-and-control discovery, making takedowns and infrastructure mapping more difficult. Reported infection activity includes retrieval of a shell script aic.sh from 212.104.141[.]140 that establishes persistence via a cron job (running at the 55-minute mark each hour) and deploys an ELF payload (noted as kad) to install the client; infected nodes also query external IP and use NTP lookups for timing/uptime checks. Compromised devices are then monetized through a proxy service branded Doppelgänger (doppelganger[.]shop), assessed as a rebrand of Faceless, a proxy operation previously associated with TheMoon malware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Lumen said it had blocked traffic to and from KadNap's control infrastructure across its own network and planned to release indicators of compromise. This marked the first reported defensive response tied to the botnet's public disclosure.
In its public reporting, Black Lotus Labs revealed that KadNap used a custom Kademlia-based peer-to-peer architecture to obscure command-and-control infrastructure, making takedowns more difficult. Researchers also identified a weakness in the design: infected devices consistently contacted two intermediary nodes before reaching C2, providing defenders with a way to identify control infrastructure.
Black Lotus Labs assessed that access to KadNap-compromised devices was being sold through the Doppelganger proxy service, believed to be a rebrand of Faceless and associated with cybercrime activity such as brute-force attacks and targeted exploitation. This attribution connected the botnet to a broader malicious proxy ecosystem.
From its initial discovery in August 2025, KadNap expanded from about 10,000 daily infections to more than 14,000 compromised devices by March 2026. Most victims were located in the United States, with additional infections reported in countries including Taiwan, Hong Kong, the U.K., Brazil, France, Italy, Spain, and Russia.
Lumen's Black Lotus Labs first observed the KadNap malware campaign in August 2025, targeting primarily ASUS routers and other edge networking devices. The botnet used shell scripts, cron-based persistence, and ELF payloads to enroll ARM- and MIPS-based systems into a proxy network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.