Close ad

The Internet is full of all kinds of threats these days, but every now and then something pops up that can really worry security experts. That's exactly what's happening now with a new type of malware called KadNap. According to security company Lumen, cybercriminals have managed to secretly take control of more than 14 devices around the world and turn them into a cyber weapon that is extremely difficult to stop. These are not servers or powerful computers in data centers. The attackers are using devices that are in the homes of a huge number of people, typically routers. And it is precisely those from the Asus brand that make up the majority of infected devices that have become part of the new botnet network.

Router as a tool for cyberattack

The principle is relatively simple. The KadNap malware attacks an internet-connected device, takes control of it, and then joins it in a so-called botnet. This is in practice a network of thousands to millions of devices that attackers can remotely control and use for various malicious activities.

For example, such devices send a huge number of requests to specific websites or online services. The result is a so-called DDoS attack, in which the server is overwhelmed with traffic and simply stops working. Pro To a regular user, this means that the website or service is unavailable.

Interestingly, it's not just routers that can be compromised by a botnet. Cybercriminals are increasingly targeting devices that fall into the Internet of Things category. These include smart cameras, home appliances, and even smart refrigerators. Once such a device is connected to the Internet and contains a security flaw, it becomes a potential target.

ProNo. KadNap is so problematic

According to security experts, KadNap is unique in the way it works. Unlike classic botnets, it does not use a central server that could be relatively easily shut down. Instead, it operates on a decentralized peer-to-peer system, where individual devices communicate directly with each other.

This is what makes it an exceptionally resilient infrastructure. If some parts of the network are shut down, the rest can continue to function without any problems. Pro This makes it significantly more difficult for security experts and the police to eliminate than for traditional botnets.

Another problem is that attacks conducted through home routers look like regular traffic to the Internet. In other words, security systems see the traffic as coming from regular home IP addresses, not from suspicious servers or known attack networks.

Infected devices are all over the world

The largest number of infected devices are located in the United States, according to researchers, but that's far from the only region. KadNap has also been detected in the United Kingdom, Australia, Brazil, Russia, and across Europe.

Pro The infection may be practically invisible to the average user. If the router is compromised, the owner will usually notice maxexcept that the internet sometimes seems a little slower than usual. Otherwise, the device seems to work normally. As a result, this is an extremely interesting and at the same time quite dangerous attack. 

Today's most read

.