TF-MAL-elf.kadnap
📛 Threat Title
Malware family: KadNap
Description
ThreatFox malware family `elf.kadnap`. Printable name: KadNap.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.kadnap
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kadnap
IOC database
- Type
- domain
- Value
elf.kadnap- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.kadnap
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kadnap
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arstechnica.com
THE KADNAP IS OUT OF THE BAG 14,000 routers are infected by malware that's highly resistant to takedowns Most of the devices are made by Asus and are located in the US.
-
web:cyberpress.org
To protect against the KadNap malware and prevent devices from being conscripted into this malicious proxy network, security experts recommend several critical mitigation strategies: Keep firmware updated: Regularly check for and install the latest security patches provided by the router manufacturer to close known vulnerabilities.
-
web:gbhackers.com
A newly uncovered malware campaign dubbed KadNap has silently conscripted more than 14,000 internet‑exposed routers and edge devices into a stealth proxy botnet.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
-
web:malware.news
The Black Lotus Labs team at Lumen has discovered a sophisticated new malware named " KadNap ." This threat primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. Since August 2025, we have been monitoring the growth of this network, which is now above 14,000 infected devices. Introduction to Malware Binary Triage (IMBT) Course Looking to level up ...
-
web:securityaffairs.com
KadNap malware infects 14,000+ edge devices turning them into a stealth proxy botnet used to route malicious internet traffic.
-
web:securityarsenal.com
KadNap malware has hijacked over 14,000 Asus routers to create a stealth proxy botnet. Learn detection and mitigation strategies.
-
web:thehackernews.com
KadNap botnet infects 14,000+ routers using DHT-based P2P control while ClipXDaemon hijacks crypto wallets on Linux X11.
-
web:www.broadcom.com
Researchers at Black Lotus Labs recently uncovered KadNap , an advanced botnet strain that has successfully compromised over 14,000 routers since August 2025. The malware employs sophisticated evasion strategy by utilizing a customized version of the Kademlia Distributed Hash Table (DHT) protocol to establish a decentralized, peer-to-peer (P2P ...
-
web:www.lumen.com
Malware analysis Once the ELF file from the malware server is loaded, it begins the process of installing KadNap . In addition to creating a "phone tree" for finding the hidden C2 addresses, the malware was designed with some versatility—Black Lotus Labs identified samples of KadNap for both ARM and MIPS processors.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.