Threat reportMalwareTL-2026-0206
KadNap P2P Botnet — 14,000+ Asus Routers Compromised via Custom Kademlia DHT C2
KadNap P2P Botnet (TL-2026-0206), also tracked as KadNap, is a high-severity malware campaign scored CVSS 8.1, first published 2026-03-10. It carries a reported Russia nexus and is not formally attributed, affects Asus Home and SOHO Routers, maps to 14 MITRE ATT&CK techniques (T1016, T1027, T1036), and is covered by 9 detection rules and 26 indicators of compromise.
- CVSS
- 8.1/10High
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0206
- Threat ID
- TL-2026-0206
- Also known as
- KadNap, Silence of the Hops
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- consumer, small-business, telecommunications, financial, government, healthcare
- Target regions
- North America, East Asia, Europe, Oceania, South America
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in KadNap P2P Botnet
Malware and tooling: KadNap, Custom Kademlia DHT
How KadNap P2P Botnet works
Large-scale botnet targeting Asus home and SOHO routers using a custom Kademlia DHT-based peer-to-peer C2 infrastructure. Over 14,000 compromised devices (60% in the US) are monetized through the Doppelganger proxy-as-a-service, a rebrand of the Faceless service previously powered by TheMoon malware. Active since August 2025 with ARM and MIPS ELF binaries.
KadNap is a sophisticated botnet malware discovered by Lumen Black Lotus Labs that primarily targets Asus home and SOHO routers, though it has been observed infecting other edge networking devices. The malware was first detected in August 2025 with approximately 10,000 compromised devices, growing to over 14,000 daily distinct victims by February 2026.
The infection chain begins with a shell script (aic.sh) downloaded from the initial staging server at 212.104.141.140. This script establishes persistence by creating a cron job that executes at the 55-minute mark of every hour, pulling and executing a malicious shell script renamed to .asusrouter stored at /jffs/.asusrouter. The script then downloads an architecture-appropriate ELF binary (supporting ARM and MIPS processors), renames it to 'kad', and executes it.
KadNap's most notable feature is its custom implementation of the Kademlia Distributed Hash Table (DHT) protocol for command-and-control communications. Upon execution, the malware forks a child process that connects to BitTorrent DHT bootstrap nodes to discover peers. It generates infohashes by creating a bencoded string using an XOR key computed from NTP server time (querying time-a.nist.gov, time-b.nist.gov, time.windows.com, ntp.asql.co.uk, chronos.csr.net) combined with system uptime. A hardcoded 0x40-byte string (6YL5aNSQv9hLJ42aDKqmnArjES4jxRbfPTnZDdBdpRhJkHJdxqMQmeyCrkg2CBQg) is SHA-1 hashed to derive AES encryption keys for peer communications.
Two persistent DHT nodes at 45.135.180.38 and 45.135.180.177 serve as stable entry points into the botnet's P2P network. Once a bot contacts these nodes, it receives C2 configuration files: .sose (stored at /tmp/.sose containing C2 IP:port pairs) and fwr.sh (stored at /tmp/.fwr.sh containing firewall rules). The malware actively blocks SSH access on port 22 to prevent administrator remediation.
The botnet infrastructure is segmented by device type, with separate C2 servers for Asus routers versus other edge devices. On average, three to four C2 servers are active at any given time. The operator infrastructure includes servers at 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, and 79.141.161.152.
Compromised devices are monetized through a proxy-as-a-service called Doppelganger (doppelganger.shop), which launched in May/June 2025 and is assessed to be a rebrand of the Faceless proxy service previously powered by TheMoon malware victims. Doppelganger claims to offer residential proxies across 50+ countries with '100% anonymity' and is specifically tailored for criminal activity including credential stuffing, brute-force attacks, and other malicious operations.
Geographically, over 60% of infected devices are located in the United States, with additional concentrations in Taiwan (5%), Hong Kong (5%), Russia (5%), and victims across the UK, Australia, Brazil, France, Italy, and Spain.
---
**Revalidated on 2026-03-12**
POST-DISCLOSURE UPDATE (2026-03-12): Following the March 10 public disclosure, Lumen has proactively null-routed all KadNap C2 traffic traversing its backbone infrastructure, providing partial disruption for traffic that routes through Lumen-operated networks. IOCs have been pushed to public threat intelligence feeds. However, due to KadNap's decentralized P2P architecture leveraging the Kademlia DHT protocol, the botnet remains structurally resilient — sinkholing individual nodes does not collapse the mesh, and infected devices will re-discover peers through DHT bootstrap. The Doppelganger proxy-as-a-service marketplace (doppelganger.shop) remains operational with no reported domain seizure or law enforcement action.
Two critical ASUS vulnerabilities disclosed in November 2025 — CVE-2025-59366 (CVSS 9.8, AiCloud authentication bypass via path traversal + OS command injection) and CVE-2025-59367 (CVSS 9.3, DSL router authentication bypass granting immediate administrative control) — affect the same ASUS router families targeted by KadNap. While no direct exploitation of these CVEs by KadNap operators has been confirmed (assessed primary vector remains credential-based access), the overlap in affected device population represents a significant amplification risk. Organizations should treat firmware patching for these CVEs as an urgent priority alongside KadNap-specific IOC blocking.
Multiple industry sources now confirm KadNap-compromised nodes are actively leveraged for credential stuffing campaigns, DDoS amplification, and brute-force attacks proxied through residential IP addresses, making detection by target organizations significantly harder due to the legitimate-appearing source IPs.
MITRE ATT&CK techniques used in TL-2026-0206
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
command-and-control
T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
initial-access
T1190 Exploit Public-Facing Application
impact
resource-development
defense-impairment
Affected products and versions in KadNap P2P Botnet
- Asus — Home and SOHO Routers
Vulnerable versions: Multiple models with default/weak credentials; End-of-life firmware
Fixed in: Latest firmware with hardened SSH configuration - Various — Edge Networking Devices
Vulnerable versions: ARM architecture devices; MIPS architecture devices
Remediation for KadNap P2P Botnet
Patches
- Apply latest Asus firmware updates for all router models
- Enable automatic firmware updates where supported
Immediate actions
- Reboot affected Asus routers to clear in-memory malware
- Block connections to known C2 IPs: 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, 79.141.161.152
- Block connections to DHT nodes: 45.135.180.38, 45.135.180.177
- Block initial staging server: 212.104.141.140
- Monitor for outbound connections to BitTorrent DHT bootstrap nodes from router infrastructure
- Check for presence of /jffs/.asusrouter and /tmp/.sose files on Asus devices
Workarounds
- Change default router admin credentials immediately
- Disable remote management interfaces (WAN-side access)
- Disable SSH access if not required, or restrict to LAN-only
- Schedule regular router reboots to clear non-persistent malware components
- Block outbound connections on non-standard ports from router devices
Longer-term hardening
- Replace end-of-life Asus routers no longer receiving firmware updates
- Deploy network monitoring for anomalous P2P traffic from edge devices
- Implement network segmentation to isolate SOHO router management interfaces
- Deploy DNS sinkholing for known Doppelganger infrastructure
- Monitor for residential IP proxy abuse in authentication logs
Weaknesses (CWE) in KadNap P2P Botnet
Timeline of KadNap P2P Botnet
- Doppelganger proxy-as-a-service (doppelganger.shop) launched, assessed as rebrand of Faceless service previously powered by TheMoon malware
- KadNap botnet first detected by Lumen Black Lotus Labs with approximately 10,000 compromised devices
- Sharp increase in KadNap infections observed; operators stabilized and grew victim pool
- KadNap botnet maintained approximately 14,000 daily distinct victims with 60% concentration in the United States
- Active C2 infrastructure identified: 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, 79.141.161.152
- Persistent Kademlia DHT network nodes confirmed active at 45.135.180.38 and 45.135.180.177
- Broad industry coverage published: The Hacker News, BleepingComputer, SC Media, TechRadar, SecurityAffairs, CSA, Aviatrix, TechNadu, and others amplify the disclosure
- Lumen null-routes all KadNap C2 traffic on its backbone and begins distributing IOCs to public threat intelligence feeds
- Lumen Black Lotus Labs publicly discloses KadNap botnet with full technical analysis and IOCs released on GitHub
- CSA (Cloud Security Alliance) publishes CISO Briefing with enterprise mitigation guidance specific to KadNap DHT evasion on ASUS edge devices
- Revalidation confirms botnet remains active; Doppelganger proxy service operational; no full takedown achieved despite Lumen backbone blocking
- As of 2026-05-29, KadNap remains active: ~14,000 daily Asus/edge-router victims persist and the Doppelganger proxy service stays operational, with no law-enforcement seizure. Lumen's March 10 disclosure only null-routed C2 on its own backbone; the P2P Kademlia-DHT design resists takedown, and no successor supersedes it.
Sources cited for KadNap P2P Botnet
- Lumen Black Lotus Labs - Silence of the Hops: The KadNap Botnet
- KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet - The Hacker News
- New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network - BleepingComputer
- Black Lotus Labs IOCs - KadNap_IOCs.txt
- ASUS Security Advisory - Latest Vulnerability Updates
- GreyNoise - Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
- TheMoon Botnet Resurfaces Exploiting EoL Devices to Power Criminal Proxy - The Hacker News
- Lumen Black Lotus Labs - The Dark Side of TheMoon
Detection coverage for TL-2026-0206
As of 2026-03-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0206 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.