ANAVEM
Reference
Languagefr
Multiple wireless routers with red warning lights in dark server environment

KadNap Malware Hijacks 14,000 Asus Routers for Botnet

New KadNap malware has infected over 14,000 Asus routers since August 2025, creating a botnet for proxying malicious traffic.

Emanuel DE ALMEIDAEmanuel DE ALMEIDA
10 Mar 2026, 17:00 2 min read 3

Last updated 16 Mar 2026, 01:34

SEVERITYHigh
EXPLOITActive Exploit
PATCH STATUSUnavailable
VENDORAsus
AFFECTEDAsus routers (specific models ...
CATEGORYMalware

Key Takeaways

KadNap Malware Campaign Targets Asus Router Infrastructure

Security researchers at Black Lotus Labs discovered a new malware strain called KadNap that's systematically compromising Asus routers to build a proxy botnet. The campaign began in August 2025 and has steadily expanded its reach over the past seven months.

The malware transforms infected routers into proxy nodes that route malicious traffic, effectively turning home and business networks into unwitting accomplices in cybercriminal operations. Attackers leverage the compromised devices to mask their true locations and evade detection systems.

14,000 Asus Routers Compromised Across Global Networks

The botnet has infected more than 14,000 Asus router devices worldwide, with the United States bearing the brunt of the attack. Over 60% of compromised devices are located within U.S. networks, making American home and business users the primary targets.

The remaining 40% of infections span international networks, though specific regional breakdowns weren't disclosed in the research findings. All affected devices appear to be Asus-branded routers, suggesting the malware exploits vendor-specific vulnerabilities or configuration weaknesses.

Router Owners Must Check for Compromise and Apply Patches

Asus router administrators should immediately check their devices for signs of compromise and ensure firmware is updated to the latest version. The CISA Known Exploited Vulnerabilities catalog provides guidance on identifying compromised network infrastructure.

Network monitoring tools can detect unusual proxy traffic patterns that indicate KadNap infection. Organizations should also review their security update processes to prevent similar router-based attacks from succeeding in the future.

Frequently Asked Questions

How can I tell if my Asus router is infected with KadNap malware?+
Check for unusual network traffic patterns, slower internet speeds, or unexpected proxy connections. Monitor your router's admin logs for suspicious activity and ensure your firmware is updated to the latest version.
What does KadNap malware do to infected Asus routers?+
KadNap transforms compromised routers into proxy nodes that route malicious traffic for cybercriminals. This allows attackers to hide their true locations and evade security detection systems.
Which countries are most affected by the KadNap router botnet?+
The United States accounts for over 60% of the 14,000+ infected devices. The remaining 40% are distributed across international networks, though specific regional breakdowns weren't disclosed.
Emanuel DE ALMEIDA
About the Author

Emanuel DE ALMEIDA

Senior IT Journalist & Cloud Architect

Microsoft MCSA-certified Cloud Architect | Fortinet-focused. I modernize cloud, hybrid & on-prem infrastructure for reliability, security, performance and cost control - sharing field-tested ops & troubleshooting.

Discussion

Share your thoughts and insights

You must be logged in to comment.

Loading comments...