Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Aug 30, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016.
Profile source: Mallory opens in a new tabHajime
Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016. Written in C and designed for multiple embedded-device architectures, it primarily targets Internet-exposed routers, cameras, DVRs, cable modems, and other Linux-based IoT systems. Hajime propagates through Telnet credential brute forcing, TR-069 command-execution abuse, an Arris cable-modem password mechanism, and, in later variants, exploitation of GPON router vulnerabilities including CVE-2018-10561 and CVE-2018-10562. It identifies device architecture and distributes an appropriate payload to compromised hosts.
Hajime uses a decentralized DHT-based peer-to-peer architecture rather than conventional centralized command-and-control. Nodes synchronize configuration, propagation, and execution modules over UDP-based uTP communications. The malware uses authenticated module distribution and cryptographic protections for peer communications and synchronized files, complicating sinkholing and takedown efforts. Hajime has been observed scanning for vulnerable services, brute forcing common default credentials, and spreading to additional devices. It also blocks some ports commonly used by competing IoT malware, which can incidentally inhibit subsequent infections.
Unlike Mirai-derived botnets, Hajime has not been observed deploying denial-of-service or other disruptive attack modules in the wild; observed functionality has predominantly focused on propagation. Some variants leave a message claiming a white-hat purpose, but this assertion is unverified and does not alter the unauthorized nature of compromise. Hajime infections have been observed globally, with significant concentrations reported in Iran, Brazil, Vietnam, Russia, and Turkey.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.