Skip to content

Kaiji

Kaiji is a Go-based Linux botnet and distributed-denial-of-service malware family targeting Linux servers and IoT devices.

Profile source: Mallory opens in a new tab

Kaiji

Family profile

Kaiji is a Go-based Linux botnet and distributed-denial-of-service malware family targeting Linux servers and IoT devices. It has propagated through SSH brute-forcing of root accounts, abuse of exposed Docker APIs, and post-exploitation deployment following server-side remote-code-execution compromises. Kaiji supports multiple TCP-, UDP-, and spoofing-based flood attacks, executes attacker-supplied shell commands, and can use compromised systems to relay malicious traffic. It establishes persistence through Linux startup services, scheduled tasks, shell initialization, and modification of startup mechanisms. Variants have masqueraded as system utilities, removed competing processes or unnecessary binaries, altered host security settings, and used watchdog behavior to restart or reboot hosts when the payload is terminated. Kaiji can attempt further spread using locally available SSH keys and host information recovered from shell history. Chaos has been assessed as an evolutionary descendant of Kaiji based on code overlap.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Scanning

Exploited software

Vulnerabilities linked to Kaiji

2 CVEs

MITRE ATT&CK

Kaiji in ATT&CK

30 distinct techniques

Reporting

Research mentioning Kaiji

Sep 3
Malware News

Creating EMBeD, the Embedded Malware Benchmark Dataset - Malware Analysis - Malware Analysis, News and Indicators

Researchers at CrySyS Lab presented EMBeD (Embedded Malware Benchmark Dataset), a proposed public benchmark intended to make IoT malware-binary detection research more reproducible and comparable. The dataset addresses reliance on proprietary collections, inconsistent malware-family labels, and undisclosed machine-learning training and test splits by providing balanced, consistently labeled samples. EMBeD extracts sample metadata, filters unreliable binaries, and derives and validates family labels using weighted VirusTotal detections and TLSH-based similarity graphs. Its proof of concept processed 67,800 MIPS IoT-malware samples and produced seven families—Mirai, Gafgyt, Hajime, Kaiji, Tsunami, DDoSTF, and Dofloo—with 100 samples per family; planned releases will expand coverage and add architectures including ARM using sources such as VirusTotal and Ukatemi's Kaibou Repo.

Sep 3
Crysys

Creating EMBeD, the Embedded Malware Benchmark Dataset - CrySyS Blog

Aug 5
Cloud Security Alliance

New Chaos Malware Variant Exploiting Misconfigurations | CSA

Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.

Sep 28
Lumen Black Lotus Labs

Chaos is a Go-based Swiss army knife of malware

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.