KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

Cybersecurity researchers have identified KadNap, a new malware that has compromised over 14,000 edge devices, primarily Asus routers, to build a resilient proxy botnet using decentralized P2P protocols.
Cybersecurity researchers have discovered a new malware called KadNap that's primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic.
The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than 60% of victims located in the U.S., according to the Black Lotus Labs team at Lumen. A lesser number of infections have been detected in Taiwan, Hong Kong, Russia, the U.K., Australia, Brazil, France, Italy, and Spain.
"KadNap employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring," the cybersecurity company said in a report shared with The Hacker News.
Compromised nodes in the network leverage the DHT protocol to locate and connect with a command-and-control (C2) server, thereby making it resilient to detection and disruption efforts. Once devices are successfully compromised, they are marketed by a proxy service named Doppelgänger, which is assessed to be a rebrand of Faceless, another proxy service associated with TheMoon malware.
Central to the attack is a shell script ("aic.sh") that's downloaded from the C2 server, which initiates the process of conscripting the victim to the P2P network. The malware is capable of targeting devices running both ARM and MIPS processors.
In a separate development, researchers detailed a new Linux threat dubbed ClipXDaemon. This clipper malware is designed to target cryptocurrency users by intercepting and altering copied wallet addresses in X11 environments. Staged entirely in memory, it employs stealth techniques such as process masquerading and avoids Wayland sessions to bypass security controls.
Source: The Hacker News















