# KadNap P2P Botnet — 14,000+ Asus Routers Compromised via Custom Kademlia DHT C2

> Large-scale botnet targeting Asus home and SOHO routers using a custom Kademlia DHT-based peer-to-peer C2 infrastructure. Over 14,000 compromised devices (60% in the US) are monetized through the Doppelganger proxy-as-a-service, a rebrand of the Faceless service previously powered by TheMoon malware. Active since August 2025 with ARM and MIPS ELF binaries.

- **Published:** 2026-03-10T12:00:00Z
- **Last reviewed:** 2026-03-10T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0206
- **ID:** TL-2026-0206
- **Severity:** HIGH (CVSS 8.1)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

KadNap is a sophisticated botnet malware discovered by Lumen Black Lotus Labs that primarily targets Asus home and SOHO routers, though it has been observed infecting other edge networking devices. The malware was first detected in August 2025 with approximately 10,000 compromised devices, growing to over 14,000 daily distinct victims by February 2026.

The infection chain begins with a shell script (aic.sh) downloaded from the initial staging server at 212.104.141.140. This script establishes persistence by creating a cron job that executes at the 55-minute mark of every hour, pulling and executing a malicious shell script renamed to .asusrouter stored at /jffs/.asusrouter. The script then downloads an architecture-appropriate ELF binary (supporting ARM and MIPS processors), renames it to 'kad', and executes it.

KadNap's most notable feature is its custom implementation of the Kademlia Distributed Hash Table (DHT) protocol for command-and-control communications. Upon execution, the malware forks a child process that connects to BitTorrent DHT bootstrap nodes to discover peers. It generates infohashes by creating a bencoded string using an XOR key computed from NTP server time (querying time-a.nist.gov, time-b.nist.gov, time.windows.com, ntp.asql.co.uk, chronos.csr.net) combined with system uptime. A hardcoded 0x40-byte string (6YL5aNSQv9hLJ42aDKqmnArjES4jxRbfPTnZDdBdpRhJkHJdxqMQmeyCrkg2CBQg) is SHA-1 hashed to derive AES encryption keys for peer communications.

Two persistent DHT nodes at 45.135.180.38 and 45.135.180.177 serve as stable entry points into the botnet's P2P network. Once a bot contacts these nodes, it receives C2 configuration files: .sose (stored at /tmp/.sose containing C2 IP:port pairs) and fwr.sh (stored at /tmp/.fwr.sh containing firewall rules). The malware actively blocks SSH access on port 22 to prevent administrator remediation.

The botnet infrastructure is segmented by device type, with separate C2 servers for Asus routers versus other edge devices. On average, three to four C2 servers are active at any given time. The operator infrastructure includes servers at 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, and 79.141.161.152.

Compromised devices are monetized through a proxy-as-a-service called Doppelganger (doppelganger.shop), which launched in May/June 2025 and is assessed to be a rebrand of the Faceless proxy service previously powered by TheMoon malware victims. Doppelganger claims to offer residential proxies across 50+ countries with '100% anonymity' and is specifically tailored for criminal activity including credential stuffing, brute-force attacks, and other malicious operations.

Geographically, over 60% of infected devices are located in the United States, with additional concentrations in Taiwan (5%), Hong Kong (5%), Russia (5%), and victims across the UK, Australia, Brazil, France, Italy, and Spain.

---

**Revalidated on 2026-03-12**

POST-DISCLOSURE UPDATE (2026-03-12): Following the March 10 public disclosure, Lumen has proactively null-routed all KadNap C2 traffic traversing its backbone infrastructure, providing partial disruption for traffic that routes through Lumen-operated networks. IOCs have been pushed to public threat intelligence feeds. However, due to KadNap's decentralized P2P architecture leveraging the Kademlia DHT protocol, the botnet remains structurally resilient — sinkholing individual nodes does not collapse the mesh, and infected devices will re-discover peers through DHT bootstrap. The Doppelganger proxy-as-a-service marketplace (doppelganger.shop) remains operational with no reported domain seizure or law enforcement action.

Two critical ASUS vulnerabilities disclosed in November 2025 — CVE-2025-59366 (CVSS 9.8, AiCloud authentication bypass via path traversal + OS command injection) and CVE-2025-59367 (CVSS 9.3, DSL router authentication bypass granting immediate administrative control) — affect the same ASUS router families targeted by KadNap. While no direct exploitation of these CVEs by KadNap operators has been confirmed (assessed primary vector remains credential-based access), the overlap in affected device population represents a significant amplification risk. Organizations should treat firmware patching for these CVEs as an urgent priority alongside KadNap-specific IOC blocking.

Multiple industry sources now confirm KadNap-compromised nodes are actively leveraged for credential stuffing campaigns, DDoS amplification, and brute-force attacks proxied through residential IP addresses, making detection by target organizations significantly harder due to the legitimate-appearing source IPs.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1016 System Network Configuration Discovery
- T1082 System Information Discovery
- T1090 Proxy
- T1095 Non-Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1583 Acquire Infrastructure
- T1496 Resource Hijacking

## Sources

- [Lumen Black Lotus Labs - Silence of the Hops: The KadNap Botnet](https://blog.lumen.com/silence-of-the-hops-the-kadnap-botnet/)
- [KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet - The Hacker News](https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html)
- [New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network - BleepingComputer](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/)
- [Black Lotus Labs IOCs - KadNap_IOCs.txt](https://github.com/blacklotuslabs/IOCs/blob/main/KadNap_IOCs.txt)
- [ASUS Security Advisory - Latest Vulnerability Updates](https://www.asus.com/security-advisory/)
- [GreyNoise - Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers](https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers)
- [TheMoon Botnet Resurfaces Exploiting EoL Devices to Power Criminal Proxy - The Hacker News](https://thehackernews.com/2024/03/themoon-botnet-resurfaces-exploiting.html)
- [Lumen Black Lotus Labs - The Dark Side of TheMoon](https://blog.lumen.com/the-darkside-of-themoon/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0206
