Skip to content

Hajime

Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016.

Profile source: Mallory opens in a new tab

Hajime

Family profile

Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016. Written in C and designed for multiple embedded-device architectures, it primarily targets Internet-exposed routers, cameras, DVRs, cable modems, and other Linux-based IoT systems. Hajime propagates through Telnet credential brute forcing, TR-069 command-execution abuse, an Arris cable-modem password mechanism, and, in later variants, exploitation of GPON router vulnerabilities including CVE-2018-10561 and CVE-2018-10562. It identifies device architecture and distributes an appropriate payload to compromised hosts.

Hajime uses a decentralized DHT-based peer-to-peer architecture rather than conventional centralized command-and-control. Nodes synchronize configuration, propagation, and execution modules over UDP-based uTP communications. The malware uses authenticated module distribution and cryptographic protections for peer communications and synchronized files, complicating sinkholing and takedown efforts. Hajime has been observed scanning for vulnerable services, brute forcing common default credentials, and spreading to additional devices. It also blocks some ports commonly used by competing IoT malware, which can incidentally inhibit subsequent infections.

Unlike Mirai-derived botnets, Hajime has not been observed deploying denial-of-service or other disruptive attack modules in the wild; observed functionality has predominantly focused on propagation. Some variants leave a message claiming a white-hat purpose, but this assertion is unverified and does not alter the unauthorized nature of compromise. Hajime infections have been observed globally, with significant concentrations reported in Iran, Brazil, Vietnam, Russia, and Turkey.

Capabilities

  • Brute Force
  • Initial Access
  • Reconnaissance
  • Scanning

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Aug 30, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • MD1

Leading providers

  • ALEXHOST SRL1

Infrastructure traits

  • Hosting 1

Exploited software

Vulnerabilities linked to Hajime

5 CVEs

MITRE ATT&CK

Hajime in ATT&CK

15 distinct techniques

Reporting

Research mentioning Hajime

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.