Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

littlemissmartypants

(32,830 posts)
Wed Mar 11, 2026, 05:46 PM 11 hrs ago

14,000 routers are infected by malware that's highly resistant to takedowns

Most of the devices are made by Asus and are located in the US.

Dan Goodin – Mar 11, 2026 5:27 PMResearchers say they have uncovered a takedown-resistant botnet of 14,000 routers and other network devices—primarily made by Asus—that have been conscripted into a proxy network that anonymously carries traffic used for cybercrime.

The malware—dubbed KadNap—takes hold by exploiting vulnerabilities that have gone unpatched by their owners, Chris Formosa, a researcher at security firm Lumen’s Black Lotus Labs, told Ars. The high concentration of Asus routers is likely due to botnet operators acquiring a reliable exploit for vulnerabilities affecting those models. He said it’s unlikely that the attackers are using any zero-days in the operation.

A botnet that stands out among others
The number of infected routers averages about 14,000 per day, up from 10,000 last August, when Black Lotus discovered the botnet. Compromised devices are overwhelmingly located in the US, with smaller populations in Taiwan, Hong Kong, and Russia. One of the most salient features of KadNap is a sophisticated peer-to-peer design based on Kademlia, a network structure that uses distributed hash tables to conceal the IP addresses of command-and-control servers. The design makes the botnet resistant to detection and takedowns through traditional methods.

“The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control,” Formosa and fellow Black Lotus researcher Steve Rudd wrote Wednesday. “Their intention is clear: avoid detection and make it difficult for defenders to protect against.”
...
https://arstechnica.com/security/2026/03/14000-routers-are-infected-by-malware-thats-highly-resistant-to-takedowns/

1 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
14,000 routers are infected by malware that's highly resistant to takedowns (Original Post) littlemissmartypants 11 hrs ago OP
Uggh... The first two comments: hlthe2b 10 hrs ago #1

hlthe2b

(113,685 posts)
1. Uggh... The first two comments:
Wed Mar 11, 2026, 06:34 PM
10 hrs ago


flerchin Ars Scholae Palatinae
I don't grok how to know if I'm infected from the KadNap_IOCs.txt.

59 minutes ago
aventari Wise, Aged Ars Veteran
flerchin said:
I don't grok how to know if I'm infected from the KadNap_IOCs.txt.

I would assume you grep your router network logs for the IPs. You need to grok grep though


Excuse me while I go throw up at the inanity.
Latest Discussions»General Discussion»14,000 routers are infect...