7 min read

Your Router Has Been Working Against You

A new malware campaign quietly confirmed something that security professionals have been saying for years: the network edge is not a boundary. It is a battlefield. And for most organizations, it has been lost without anyone noticing.

What the Research Found

On 10 March 2026, researchers at Black Lotus Labs, part of Lumen Technologies, published findings on a malware strain they named KadNap. According to their report, KadNap has infected more than 14,000 edge devices since it was first detected in the wild in August 2025. The primary target is Asus routers, though Lumen confirmed the operators have deployed it against a broader range of edge networking devices.

More than 60 percent of identified victims are located in the United States, with additional infections recorded in Taiwan, Hong Kong, Russia, the UK, Australia, Brazil, France, Italy, and Spain.

Once a device is compromised, it is enrolled into a peer-to-peer proxy botnet. The infected nodes are marketed through a service called Doppelganger, which Lumen assesses to be a rebranding of Faceless, a proxy operation previously linked to the TheMoon malware family. Doppelganger claims to provide residential proxy coverage across more than 50 countries.

Why This Is Harder to Detect Than Most Threats

The technical design of KadNap is what distinguishes it from older botnet architectures. Rather than using a fixed command-and-control server, it uses a custom implementation of the Kademlia Distributed Hash Table (DHT) protocol, the same peer-to-peer communication layer that underpins many decentralized networks.

This means there is no single IP address to block, no domain to sink-hole, and no easily identifiable server to take offline. Infected devices locate each other through the DHT network and receive instructions through that decentralized mesh. Lumen described the design as deliberately structured to hide malicious traffic within the noise of legitimate peer-to-peer activity.

The malware closes port 22 on infected devices, disabling SSH access. The device keeps functioning normally. There is nothing obviously wrong. The router just stops being yours.

The infection chain begins with a shell script downloaded from the C2 server. That script creates a cron job to re-download itself at the 55-minute mark of every hour, renames itself to “.asusrouter,” and executes. From there, it deploys the core malware payload, which supports both ARM and MIPS processor architectures, covering the majority of consumer and small business router hardware.

Lumen also noted that not all infected devices communicate with the same C2 infrastructure, suggesting the botnet is organized and segmented by device type and model. This is not a blunt instrument. It is a managed operation.

The Home Office Is the New Perimeter

This is not an abstract enterprise threat. The devices being compromised are the same routers sitting in home offices, remote worker environments, and small branch locations that connect directly to corporate networks through VPNs and remote access solutions.

Most organizations have spent the last several years extending their security perimeter to cover cloud infrastructure, endpoints, and identity. Very few have extended it to cover the network hardware sitting on the desk or shelf in an employee’s home. That hardware is running firmware that may not have been updated in years. The default admin password may still be in place. There is no asset register for it and no monitoring agent on it.

KadNap exploits exactly that gap. The device functions normally from the user’s perspective. Traffic passes through. Applications run. The compromised router simply also proxies malicious traffic on behalf of whoever is renting access from Doppelganger, from credential stuffing campaigns to fraud operations to further intrusion activity.

Because the traffic originates from a residential IP address associated with a legitimate employee, it passes through many detection layers that would flag activity from a known malicious infrastructure source. That is the commercial value of the proxy service and the reason this class of attack continues to grow.

Visibility Is the Starting Point

Lumen’s guidance for affected users covers the basics: keep firmware updated, reboot devices regularly, change default credentials, secure management interfaces, and replace end-of-life hardware. That advice is sound and should be followed. It does not, however, address the underlying problem, which is that most organizations do not know which edge devices exist in their distributed environment in the first place.

Before you can patch, you have to know what you have. Before you can assess whether a router is running compromised firmware, you need to know that router exists, who owns it, what it is connected to, and when it was last updated. For most enterprise and mid-market security teams managing distributed or remote workforces, that inventory simply does not exist.

This is where 4Remote operates. Our platform is built for exactly the environment that KadNap is targeting: distributed, remote-first, and edge-heavy. The platform performs continuous asset discovery across remote environments, surfacing devices that are not enrolled in corporate management systems, flagging unmanaged hardware, and identifying devices running outdated firmware or presenting known vulnerability profiles.

When a new threat campaign like KadNap emerges targeting specific hardware families, organizations with accurate, current visibility can immediately query their environment, identify exposure, and act. Organizations without it are left hoping that none of their remote workers happen to own an affected device.

The first deployment typically surfaces more than the customer expected to find.

Beyond discovery, 4Remote’s vulnerability management capabilities map identified assets against current CVE data and known exposure patterns, so security teams can prioritize remediation based on actual risk in their environment rather than generic vendor advisories.

Our Zero Trust Network Access capabilities address the parallel risk: even in environments where remote workers are using unmanaged or potentially compromised network hardware, ZTNA ensures that access to corporate resources is governed by verified identity and device posture rather than by network location. A compromised router at the network edge does not automatically grant access to internal systems when access control is implemented at the application and identity layer.

The Broader Pattern

KadNap is not an isolated incident. It follows a consistent pattern of threat actors identifying the network edge as the most consistently unmonitored part of enterprise infrastructure, particularly in organizations that have invested heavily in endpoint and cloud security without revisiting what sits between those endpoints and the internet.

TheMoon, the malware family that Doppelganger is assessed to have originated from, has been targeting edge devices since at least 2014. The infrastructure that monetizes these compromises has evolved significantly, but the fundamental attack surface has remained the same: routers, gateways, and edge devices that sit outside the perimeter of traditional security tooling and are rarely, if ever, reviewed.

The scale of the KadNap campaign, over 14,000 infected devices across multiple continents, and its operational maturity, the segmentation by device type, the decentralized C2, the commercial proxy service layered on top, indicates that this class of threat is no longer opportunistic. It is a managed, revenue-generating operation targeting a gap that most security programs have not yet closed.

What to Do

If your organization has a distributed workforce, the immediate practical steps are straightforward.

Audit what network hardware exists in remote worker environments. This is harder than it sounds without tooling designed for it, but it is the foundation of everything else. Know what devices are connecting to your corporate environment.

Verify firmware currency for any identified hardware, particularly Asus routers and other SOHO devices. The Lumen report specifically identified Asus as the primary target, though other device families are affected.

Replace end-of-life hardware. Devices that no longer receive security updates from their manufacturers are permanently exposed to emerging threats. Continuing to use them is an accepted risk that should be documented as such.

Implement Zero Trust access controls so that the security of the remote network is not a prerequisite for the security of corporate resources. This does not eliminate the threat, but it limits its impact.

If you want to understand what 4Remote can surface in your specific environment, the starting point is an asset discovery run. The results tend to be instructive.

References

Lumen Black Lotus Labs, “Silence of the Hops: The KadNap Botnet,” March 2026

The Hacker News, “KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet,” 10 March 2026

4Remote provides remote asset discovery, vulnerability management, network security, and Zero Trust access for distributed environments. For more information, visit wordpress-1325053-6351657.cloudwaysapps.com/