Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016. It primarily targets internet-exposed embedded devices, including routers, cameras, DVRs, and GPON equipment, with MIPS systems constituting a substantial portion of observed infections. Hajime propagates through Telnet credential brute forcing, targeted use of default or weak credentials, and exploitation of device vulnerabilities, including TR-069 abuse and, in later variants, GPON router flaws CVE-2018-10561 and CVE-2018-10562. Some variants also incorporated targeting logic for MikroTik devices and Arris cable modems. The malware uses a decentralized DHT-based peer-to-peer architecture for node discovery, command distribution, and module synchronization rather than conventional centralized command-and-control infrastructure. Inter-node communications use UDP-based uTP, encrypted sessions, Curve25519 key exchange, and signed modules to authenticate synchronized content. Hajime is modular, with separate propagation and execution components, and has historically focused on self-propagation rather than overt payload actions. Researchers have not observed denial-of-service or other disruptive attack modules in Hajime, although infected devices may have ports commonly targeted by competing IoT malware blocked. The operator has embedded messages portraying Hajime as a white-hat effort, but its unauthorized compromise and control of devices remains malicious activity. No reliable public attribution to a specific threat actor is available.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VPN Mentor disclosed CVE-2018-10562 as a GPON command-execution vulnerability. The content provides POST payloads abusing the router diagnostic endpoint to execute wget commands and download Muhstik components. | Hajime updated and began to infect GPON-related devices.
VPN Mentor disclosed two vulnerabilities of GPON home routers on 2018-05-01: CVE-2018-10561 authentication bypass and CVE-2018-10562 command execution vulnerabilities. From 2018-05-02 through 2018-05-10, five botnet families were observed using the GPON exploit. | Hajime updated and began to infect GPON-related devices.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
“Eventually attackers, including the Hajime botnet, exploited this vulnerability in the wild.” | CVE-2017-20149, also known as Chimay Red... affected the HTTP interface of Mikrotik routers... attackers, including the Hajime botnet, exploited this vulnerability in the wild... Greynoise continues to see active scanning for the vulnerability.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
“Find a MikroTik device by checking if the target port is open on port 8291, if this port is open,the other common web ports (80,81,82,8080,8081,8082,8089,8181,8880) will be probed next.”
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
researchers identified more than 1,350 command-and-control servers spread across 98 providers in 14 countries.
The sample represents a brand new P2P botnet implemented based on the DHT protocol... join the Mozi P2P network to become the new Mozi Bot node
Hajime utilizes a decentralized peer-to-peer network to issue commands to its bots. This makes it much harder to locate the Command-and-Control (C2) server for a takedown.
“Once the vulnerability is successfully exploited, Hajime will be downloaded and executed.”
This worm builds a huge P2P botnet... By announcing on the DHT network with a peer id similar to that day’s identifier of the configuration file we were able to be the “nearest” node and collected requests from almost every infected device... All of them were requesting Hajime config.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT-focused botnet operating through C2 infrastructure and abusing compromised routers and embedded devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.