KadNap
- Malware type
- botnet
- Family
- Malware family
- Last IoC activity
- 2026-05-15 13:16:49
- Profile updated
- 2026-07-07 14:26:18
Targeted industries: technology-and-telecommunications
Context
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Kadnap (report)
- blog.lumen.com — Silence Of The Hops The Kadnap Botnet (report)