14,000 routers infected by malware that's highly resistant to takedowns

Most of the devices are made by Asus and are located in the US.

14,000 routers infected by malware that's highly resistant to takedowns

TL;DR

  • A botnet of 14,000 routers, mainly Asus models, has been discovered, conscripted into an anonymous proxy network for cybercrime.
  • The malware, KadNap, exploits unpatched vulnerabilities, with a high concentration of Asus routers due to a reliable exploit.
  • KadNap features a sophisticated peer-to-peer design based on Kademlia, using distributed hash tables for decentralized control and resilience against takedowns.
  • The majority of infected devices are located in the US, with smaller numbers in Taiwan, Hong Kong, and Russia.
  • Black Lotus Labs has developed a method to block KadNap's control infrastructure and is distributing indicators of compromise.
  • Infected devices are used to carry traffic for Doppelganger, a fee-based proxy service.
  • To disinfect devices, a factory reset is required, and owners should ensure firmware is updated, passwords are strong, and remote access is disabled.
  • Restarting an infected device without a factory reset will result in it becoming compromised again, as KadNap stores a shell script that runs on reboot.