Threats & Adversaries · IoT / OT Attack
Researchers found KadNap controlling ~14,000 routers to run an anonymous proxy service. Most infected devices are Asus routers in the United States. The botnet's Kademlia peer-to-peer DHT hides control nodes and resists traditional takedowns.
1 source · Mar 11
Ars Technica Security
14,000 routers are infected by malware that's highly resistant to takedowns
Most of the devices are made by Asus and are located in the US.
originalPart of the PlainSec briefing for 2026-03-12
Every edition of this story: KadNap Enlists 14,000 Routers Into Resilient Proxy Botnet