KadNap Asus router proxy botnet
Malware Activity
Summary
Hide ▲
Show ▼
KadNap is a proxy botnet that compromises Asus routers and other edge devices, creating a stealth channel for malicious traffic from over 14,000 infected devices. First detected in August 2025, it uses a custom Kademlia DHT to conceal infrastructure and resist disruption. Infection relies on aic.sh, a cron-based persistence chain, and a malicious payload that runs on ARM and MIPS devices.
Related Happenings
UAT-7810 malware toolkit expansion with LONGLEASH, DOGLEASH, and JARLEASH
Malware Activity
H score27
First: 08.07.2026 17:30
Last: 08.07.2026 17:30
Sources 1
About this happening:
Chinese threat actor UAT-7810 is actively refining its bespoke malware to expand the LapDogs ORB network by breaking into internet-facing networking devices. The a...
UAT-7810 malware toolkit expansion with LONGLEASH, DOGLEASH, and JARLEASH
Malware ActivityAbout this happening: Chinese threat actor UAT-7810 is actively refining its bespoke malware to expand the LapDogs ORB network by breaking into internet-facing networking devices. The a...
Showboat / kworker Linux post-exploitation malware activity
Malware Activity
H score28
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
Researchers tied Showboat / kworker to a stealthy Linux post-exploitation framework being reused across multiple Chinese threat clusters, raising concern that a shared...
Showboat / kworker Linux post-exploitation malware activity
Malware ActivityAbout this happening: Researchers tied Showboat / kworker to a stealthy Linux post-exploitation framework being reused across multiple Chinese threat clusters, raising concern that a shared...
Operation Lightning takedown of SocksEscort proxy service
Law Enforcement
H score33
First: 13.03.2026 12:00
Last: 13.03.2026 12:00
Sources 1
About this happening:
International law enforcement partners dismantled the SocksEscort proxy service in Operation Lightning, disrupting a cybercrime network used to hide originating IP add...
Operation Lightning takedown of SocksEscort proxy service
Law EnforcementAbout this happening: International law enforcement partners dismantled the SocksEscort proxy service in Operation Lightning, disrupting a cybercrime network used to hide originating IP add...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
DOJ and Europol takedown of SocksEscort proxy network
Law Enforcement
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
U.S. and European law enforcement took down SocksEscort, a long-running cybercrime proxy network that routed traffic through compromised edge devices. The action seized...
DOJ and Europol takedown of SocksEscort proxy network
Law EnforcementAbout this happening: U.S. and European law enforcement took down SocksEscort, a long-running cybercrime proxy network that routed traffic through compromised edge devices. The action seized...
Timeline
-
10.03.2026 18:00 2 articles · 4mo ago
KadNap proxy botnet disclosure
Initial DisclosureLumen/Black Lotus Labs disclosed KadNap as a new malware family targeting Asus routers and other edge devices to build a stealth proxy botnet, with more than 14,000 infected devices and over 60% of victims in the U.S. The malware uses a custom Kademlia DHT to conceal command-and-control infrastructure, relies on aic.sh and cron-based persistence to rename and run .asusrouter and kad, can target ARM and MIPS devices, and is linked to Doppelgänger, a proxy service assessed as a rebrand of Faceless.
Show sources
- KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet — thehackernews.com — 10.03.2026 18:00
- KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet — thehackernews.com — 10.03.2026 18:00