Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Aug 26, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Kaiten, also widely known as Tsunami, is a long-running Linux IRC bot and DDoS malware family that has been extensively reused, modified, and embedded into broader botnet operations targeting internet-exposed devices and servers.
Profile source: Mallory opens in a new tabKaiten
Kaiten, also widely known as Tsunami, is a long-running Linux IRC bot and DDoS malware family that has been extensively reused, modified, and embedded into broader botnet operations targeting internet-exposed devices and servers. It is commonly associated with compromised Linux and IoT systems, including routers, cameras, embedded appliances, cloud workloads, containers, and other Unix-like environments. The malware is typically deployed after opportunistic compromise through exposed services, weak credentials, or exploitation of known vulnerabilities, and then connects to operator-controlled IRC infrastructure to receive commands.
Kaiten’s core role is as an IRC-controlled backdoor with distributed denial-of-service functionality. Variants and descendants support multiple flooding techniques and remote command execution, allowing operators to use infected hosts both for DDoS activity and for general post-compromise control. In multiple observed campaigns, Kaiten-derived bots have also been used alongside cryptominers or other payloads, reflecting its role as a modular secondary payload in Linux intrusion chains.
The family has been repeatedly incorporated into IoT botnets and malware ecosystems adjacent to Mirai and Gafgyt/Bashlite. It has appeared as a competitor process explicitly terminated by other botnets seeking exclusive control of infected devices, indicating its continued prevalence in the Linux/IoT botnet landscape. Modified Kaiten variants have also been observed using default credentials relevant to operational technology and industrial control environments, showing that generic botnet operators have adapted Kaiten-based tooling to opportunistically target exposed OT-capable devices as well.
Kaiten has also served as a code base for later malware. TeamTNT used IRC bots based on Kaiten in cloud- and container-focused campaigns, and other Linux worms and botnets have been described as based on or derived from Kaiten. In Docker-focused intrusions, Kaiten variants have been dropped together with cryptocurrency miners and persistence scripts. Across these uses, the malware remains notable less as a single modern strain than as a durable IRC bot lineage that continues to be repurposed for Linux botnet operations, DDoS attacks, persistence within compromised environments, and remote shell-style control.
Samples
Reported operators
The IRC bot, also written in C, is based on another famous IRC bot called Kaiten.
MITRE ATT&CK
Reporting
TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.