s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kadnap

📛 Threat Title

Malware family: KadNap

Category: KadNap First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kadnap`. Printable name: KadNap.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kadnap VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kadnap

IOC database

Type
domain
Value
elf.kadnap
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kadnap

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kadnap

References (1)

Remediations (10)

  • web:arstechnica.com

    THE KADNAP IS OUT OF THE BAG 14,000 routers are infected by malware that's highly resistant to takedowns Most of the devices are made by Asus and are located in the US.

  • web:cyberpress.org

    To protect against the KadNap malware and prevent devices from being conscripted into this malicious proxy network, security experts recommend several critical mitigation strategies: Keep firmware updated: Regularly check for and install the latest security patches provided by the router manufacturer to close known vulnerabilities.

  • web:gbhackers.com

    A newly uncovered malware campaign dubbed KadNap has silently conscripted more than 14,000 internet‑exposed routers and edge devices into a stealth proxy botnet.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.

  • web:malware.news

    The Black Lotus Labs team at Lumen has discovered a sophisticated new malware named " KadNap ." This threat primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. Since August 2025, we have been monitoring the growth of this network, which is now above 14,000 infected devices. Introduction to Malware Binary Triage (IMBT) Course Looking to level up ...

  • web:securityaffairs.com

    KadNap malware infects 14,000+ edge devices turning them into a stealth proxy botnet used to route malicious internet traffic.

  • web:securityarsenal.com

    KadNap malware has hijacked over 14,000 Asus routers to create a stealth proxy botnet. Learn detection and mitigation strategies.

  • web:thehackernews.com

    KadNap botnet infects 14,000+ routers using DHT-based P2P control while ClipXDaemon hijacks crypto wallets on Linux X11.

  • web:www.broadcom.com

    Researchers at Black Lotus Labs recently uncovered KadNap , an advanced botnet strain that has successfully compromised over 14,000 routers since August 2025. The malware employs sophisticated evasion strategy by utilizing a customized version of the Kademlia Distributed Hash Table (DHT) protocol to establish a decentralized, peer-to-peer (P2P ...

  • web:www.lumen.com

    Malware analysis Once the ELF file from the malware server is loaded, it begins the process of installing KadNap . In addition to creating a "phone tree" for finding the hidden C2 addresses, the malware was designed with some versatility—Black Lotus Labs identified samples of KadNap for both ARM and MIPS processors.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.