The KadNap botnet is a recently discovered malware operation, primarily targeting ASUS routers and other edge networking devices to convert them into a stealthy proxy network for cybercrime.
As of March 2026, the botnet has infected over 14,000 devices, with approximately 60% of victims located in the United States.
Key Technical Details
- Infrastructure: KadNap uses a custom version of the Kademlia Distributed Hash Table (DHT) protocol. This peer-to-peer system decentralizes control, making it difficult for defenders to locate and shut down command-and-control (C2) servers.
- Monetization: The botnet is linked to the Doppelganger proxy service (a rebrand of the “Faceless” service). It sells access to infected devices as residential proxies, allowing other cybercriminals to tunnel malicious traffic, evade blocklists, and hide their origin.
- Targeting: Nearly half of the network is currently dedicated specifically to ASUS-based bots.
How to Protect Your Router
Security researchers recommend the following steps to secure ASUS and other SOHO (Small Office/Home Office) routers:
- Update Firmware: Immediately install the latest firmware updates from the ASUS Support Page to patch known vulnerabilities.
- Perform a Factory Reset: If you suspect your router is already compromised, a full factory reset is necessary to clear persistent backdoors that might survive standard reboots.
- Disable Remote Management: Turn off features like SSH, Telnet, AiCloud, and WAN access unless they are absolutely required.
- Use Strong Credentials: Change default administrative usernames and passwords to complex, unique credentials of at least 20 characters.
- Enable AiProtection: If your model supports it, enable ASUS AiProtection (powered by Trend Micro) to detect and block malicious traffic and botnet communications.