Hajime is an IoT botnet known for compromising internet-exposed embedded devices, particularly routers and surveillance-related appliances. It has been publicly linked to exploitation of vulnerabilities in MikroTik routers and Xiongmai-based DVR, NVR, and IP camera ecosystems. Reported activity shows Hajime leveraging remotely exploitable flaws for initial access and botnet propagation, placing it in the class of opportunistic large-scale internet malware focused on recruiting vulnerable edge and IoT systems. The botnet has been associated with exploitation of CVE-2017-20149 in MikroTik routers and has also been linked by vendor reporting to exploitation of CVE-2018-10088 affecting Xiongmai devices. In the Xiongmai context, the broader intrusion pattern described around active exploitation commonly involves opening remote administration services such as telnet for follow-on control, which is consistent with botnet-oriented post-compromise tradecraft on constrained Linux-based devices. Hajime’s observed behavior aligns with scanning for exposed services, exploiting known vulnerabilities for initial access, establishing persistence within compromised devices, and using infected systems as part of a distributed botnet infrastructure. Hajime is generally tracked as a malware/botnet operation rather than a nation-state intrusion set. Based on the supplied facts, its activity is best characterized as financially or operationally motivated cybercrime-adjacent botnet activity rather than espionage. No high-confidence country of origin, specific operator identity, or narrowly defined victim geography is established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet referenced as exploiting the Chimay Red (CVE-2017-20149) Mikrotik router vulnerability in the wild.
Botnet reported by Fortinet as linked to exploitation activity against Xiongmai devices, in the context of CVE-2018-10088 exploitation claims.
Botnet reported by Fortinet as linked to exploitation activity against Xiongmai devices, in the context of CVE-2018-10088 exploitation claims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.