Recent findings reveal that approximately 14,000 routers and other network devices have been infected by a resilient malware known as KadNap. This malware primarily targets Asus devices, exploiting unpatched vulnerabilities. Chris Formosa from Lumen’s Black Lotus Labs highlighted that the prevalence of Asus routers in this botnet is likely due to the availability of effective exploits for these specific models. Notably, the botnet's daily infection rate has increased from 10,000 last August to the current figure. The majority of the compromised devices are situated in the United States, with smaller numbers found in Taiwan, Hong Kong, and Russia. A key characteristic of KadNap is its advanced peer-to-peer architecture, which utilizes Kademlia, a method that employs distributed hash tables to obscure the locations of command-and-control servers. This design significantly enhances the botnet's ability to evade detection and resist traditional takedown efforts.
14,000 Routers Compromised by Resilient Malware
A significant number of routers, primarily from Asus, are part of a botnet that is difficult to dismantle.
