Threat reportMalwareTL-2026-0212
KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for Doppelganger Proxy Network
KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for (TL-2026-0212), also tracked as KadNap, is a high-severity malware campaign, first published 2026-03-11. It is attributed to Doppelganger Proxy Operators (Russia) with low confidence, affects Asus Asus Routers (Various Models), maps to 17 MITRE ATT&CK techniques (T1008, T1016, T1027), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1Doppelganger Proxy Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-0212
- Threat ID
- TL-2026-0212
- Also known as
- KadNap, elf.kadnap
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Doppelganger Proxy Operators
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- telecommunications, residential, small-business, isp-infrastructure, government, financial
- Target regions
- North America, United States, Taiwan, Hong Kong, Russia, United Kingdom, Australia, Brazil, France, Italy, Spain
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for
Malware and tooling: KadNap
How KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for works
KadNap is a Linux botnet conscripting Asus routers and edge devices into the Doppelganger criminal proxy network using a custom Kademlia DHT protocol to hide C2 infrastructure. Active since August 2025 with 14,000 daily victims, 60% in the United States. Successor to the defunct Faceless proxy service powered by TheMoon malware.
KadNap is a sophisticated Linux botnet discovered by Lumen Black Lotus Labs that targets Asus routers and other edge networking devices running ARM and MIPS architectures. The malware employs a novel command-and-control mechanism based on a custom implementation of the Kademlia Distributed Hash Table (DHT) protocol, allowing it to conceal C2 infrastructure within legitimate BitTorrent peer-to-peer traffic.
The infection chain begins with the download of a shell script (aic.sh) from a payload delivery server. This script establishes persistence by creating a cron job that executes every hour at the 55-minute mark, ensuring the malware survives reboots and process termination. The script renames itself to .asusrouter in the /jffs/ directory — a partition on Asus routers that persists across firmware updates and reboots. It then downloads and executes the primary malicious ELF binary named 'kad', with variants compiled for both ARM and MIPS processor architectures.
The kad binary implements the custom Kademlia DHT C2 protocol through a multi-threaded architecture. First, it connects to hardcoded NTP servers (time-a.nist.gov, time-b.nist.gov, time.windows.com, ntp.asql.co.uk, chronos.csr.net) to fetch the current time and stores it alongside the host uptime. It then computes an XOR key from these timestamps combined with a hardcoded string (6YL5aNSQv9hLJ42aDKqmnArjES4jxRbfPTnZDdBdpRhJkHJdxqMQmeyCrkg2CBQg), which is SHA-1 hashed and used as an infohash for BitTorrent DHT peer discovery.
Two primary communication threads operate in parallel: a Find Peers thread that connects to BitTorrent DHT bootstrap nodes to search for infected nodes, and a Contact Peers thread that receives a 0x1000-byte encrypted buffer from discovered peers. The initial handshake uses a hardcoded AES key, and the first payload's SHA-1 hash becomes the AES key for all subsequent communications. The final peer in the chain delivers two operational files: fwr.sh (which injects iptables rules to drop incoming TCP traffic on port 22, blocking SSH access and preventing remote remediation) and .sose (a C2 configuration file stored in /tmp/).
Despite the decentralized DHT design, Black Lotus Labs identified that operators maintain two persistent final-hop DHT nodes (45.135.180.38 and 45.135.180.177), representing centralized control points and potential single points of failure. The C2 infrastructure is segmented by device type, with approximately 2 servers dedicated to Asus devices (over 50% of the botnet) and 2 servers for other edge devices.
The botnet feeds the Doppelganger proxy service (doppelganger.shop), which markets anonymous residential proxies for criminal use. Doppelganger is assessed with high confidence by both Black Lotus Labs and Spur security firm to be a successor/rebrand of the defunct Faceless proxy service, which previously monetized victims of TheMoon malware. Users of the proxy service leverage hijacked devices for brute-force credential attacks, targeted exploitation campaigns, and other malicious activities.
The botnet grew from an initial detection of 10,000+ compromised Asus devices in August 2025 to a stable plateau of approximately 14,000 daily active infected devices by December 2025 through February 2026. Geographic distribution shows 60% of victims in the United States, with additional concentrations in Taiwan (5%), Hong Kong (5%), Russia (5%), and smaller percentages in the UK, Australia, Brazil, France, Italy, and Spain.
Lumen has proactively blocked all network traffic to and from the identified control infrastructure and has distributed IOCs to public threat feeds.
---
**Revalidated on 2026-03-12**
Two days after the initial Black Lotus Labs public disclosure, KadNap has been independently confirmed and amplified by over a dozen security publishers including the Cloud Security Alliance, SC Media, Security Affairs, TechRadar, Aviatrix, and The Hacker News. The threat is assessed as fully active with no observed decline in botnet size or operational tempo.
The Cloud Security Alliance CISO Briefing (2026-03-11) identified a critical structural flaw in KadNap's architecture: despite the sophistication of the Kademlia DHT overlay, all C2 traffic ultimately routes through two persistent intermediary nodes (45.135.180.38 and 45.135.180.177). These nodes have remained consistent across all analyzed samples dating back to August 2025. This provides defenders a retroactive monitoring chokepoint -- organizations that query historical network logs for connections to these two IP addresses can determine exposure prior to this disclosure.
The CSA briefing also explicitly links two critical ASUS vulnerabilities -- CVE-2025-59366 (CVSS 9.8, AiCloud Samba authentication bypass enabling unauthenticated RCE) and CVE-2025-59367 (CVSS 9.8, DSL-series router authentication bypass granting immediate administrative control) -- as plausible initial access vectors alongside the assessed primary vector of credential stuffing. While Black Lotus Labs has not confirmed specific CVE exploitation by KadNap operators, the temporal overlap of these vulnerabilities with KadNap's growth phase warrants defensive attention.
Notably, KadNap exists within a broader pattern of sustained ASUS router targeting. The AyySSHush botnet campaign, independently discovered by GreyNoise and Censys in March 2025, compromised 9,000+ ASUS routers via persistent SSH backdoors stored in NVRAM on TCP port 53282 -- backdoors that survive firmware updates. The convergence of AyySSHush and KadNap targeting the same device ecosystem within 12 months indicates ASUS SOHO routers are a high-value, systematically exploited class of edge infrastructure.
As of 2026-03-12, no CISA advisory, coordinated law enforcement action, or official ASUS statement specifically addressing KadNap has been released. Lumen's backbone-level traffic blocking remains the primary active mitigation. The threat status remains HIGH with ACTIVE exploitation.
MITRE ATT&CK techniques used in TL-2026-0212
command-and-control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
credential-access
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
initial-access
T1190 Exploit Public-Facing Application
impact
persistence
T1547 Boot or Logon Autostart Execution
defense-impairment
Affected products and versions in KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for
- Asus — Asus Routers (Various Models)
Vulnerable versions: Multiple firmware versions — specific models not disclosed
Fixed in: Latest firmware with security patches - Various — ARM-based Edge Networking Devices
Vulnerable versions: Linux-based firmware with ARM architecture - Various — MIPS-based Edge Networking Devices
Vulnerable versions: Linux-based firmware with MIPS architecture
Remediation for KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for
Patches
- Apply latest Asus router firmware updates from official Asus support
- Enable automatic firmware updates where supported
Immediate actions
- Block all identified C2 IP addresses at network perimeter: 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, 79.141.161.152, 212.104.141.140
- Block DHT control nodes: 45.135.180.38, 45.135.180.177
- Block domain doppelganger.shop at DNS and proxy level
- Monitor for outbound connections to public BitTorrent DHT bootstrap nodes from SOHO routers
- Check Asus routers for presence of /jffs/.asusrouter or /tmp/.sose files
- Inspect cron jobs on Asus routers for hourly execution at 55-minute mark
Workarounds
- Reboot affected routers to clear active malware processes (persistence will re-download on next cron cycle unless cron job is removed)
- Factory reset affected devices and reconfigure with strong credentials
- Remove malicious cron entries and delete /jffs/.asusrouter, /tmp/.sose files manually
- Restore SSH access by flushing iptables rules if port 22 is blocked
Longer-term hardening
- Replace end-of-life Asus routers with current-generation devices
- Ensure router management interfaces are not exposed to the internet
- Implement network segmentation isolating IoT and edge devices
- Deploy network monitoring for anomalous BitTorrent DHT traffic from infrastructure devices
- Enforce strong, unique passwords on all router management interfaces
- Regularly reboot routers to clear non-persistent malware components
Timeline of KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for
- Doppelganger proxy service launched, marketing anonymous residential proxies for criminal use as successor to Faceless service
- Black Lotus Labs algorithm first detects over 10,000 Asus devices communicating with KadNap C2 servers
- Lumen Black Lotus Labs begins investigation, uncovering malicious files (aic.sh, kad binary) and C2 infrastructure
- Sharp increase in victim count observed as botnet operators stabilize infection chain and expand targeting
- Botnet reaches stable plateau of approximately 14,000 daily active infected devices, maintained through February 2026
- Active C2 IP addresses documented: 85.158.111.100, 89.46.38.74, 154.7.253.12, 212.104.141.88, 91.193.19.226, 79.141.161.152
- Persistent Kademlia DHT control nodes identified at 45.135.180.38 and 45.135.180.177
- Lumen proactively blocks all network traffic to and from identified KadNap control infrastructure across their backbone
- Black Lotus Labs publishes full technical analysis 'Silence of the Hops: The KadNap Botnet' and releases IOCs to public feeds
- SC Media, Security Affairs, TechRadar, TechNadu, Aviatrix, and VPNcentral publish independent analyses confirming KadNap findings and amplifying IOCs to wider defender community [Source: https://securityaffairs.com/189251/malware/kadnap-bot-compromises-14000-devices-to-route-malicious-traffic.html]
- Cloud Security Alliance publishes CISO Briefing on KadNap, highlighting the structural flaw of two persistent intermediary DHT nodes as a retroactive monitoring chokepoint for defenders [Source: https://labs.cloudsecurityalliance.org/research/briefing-csa-research-note-kadnap-p2p-router-botnet-dht-evas/]
- As of 2026-05-29, KadNap remains ACTIVE: the botnet still conscripts ~14,000 daily Asus/edge devices into the operating Doppelganger proxy network, with no takedown, arrests, or successor reported. Only mitigation is Lumen's backbone-level blocking; firmware-surviving /jffs persistence and decentralized DHT C2 keep it resilient, and the threat carries no CVEs (identifiers.cve empty).
Sources cited for KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for
- Silence of the Hops: The KadNap Botnet — Lumen Black Lotus Labs
- Malpedia Entry — elf.kadnap
- Black Lotus Labs KadNap IOCs — GitHub
- New KadNap Botnet Hijacks ASUS Routers — BleepingComputer
- KadNap Malware Infects 14,000+ Edge Devices — The Hacker News
- KadNap Botnet Targets Asus Routers — TechNadu
- TheMoon Malware Resurfaces — Lumen Blog (Historical Context)
Detection coverage for TL-2026-0212
As of 2026-03-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0212 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.