Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016. Written in C and designed for multiple embedded-device architectures, it primarily targets Internet-exposed routers, cameras, DVRs, cable modems, and other Linux-based IoT systems. Hajime propagates through Telnet credential brute forcing, TR-069 command-execution abuse, an Arris cable-modem password mechanism, and, in later variants, exploitation of GPON router vulnerabilities including CVE-2018-10561 and CVE-2018-10562. It identifies device architecture and distributes an appropriate payload to compromised hosts.
Hajime uses a decentralized DHT-based peer-to-peer architecture rather than conventional centralized command-and-control. Nodes synchronize configuration, propagation, and execution modules over UDP-based uTP communications. The malware uses authenticated module distribution and cryptographic protections for peer communications and synchronized files, complicating sinkholing and takedown efforts. Hajime has been observed scanning for vulnerable services, brute forcing common default credentials, and spreading to additional devices. It also blocks some ports commonly used by competing IoT malware, which can incidentally inhibit subsequent infections.
Unlike Mirai-derived botnets, Hajime has not been observed deploying denial-of-service or other disruptive attack modules in the wild; observed functionality has predominantly focused on propagation. Some variants leave a message claiming a white-hat purpose, but this assertion is unverified and does not alter the unauthorized nature of compromise. Hajime infections have been observed globally, with significant concentrations reported in Iran, Brazil, Vietnam, Russia, and Turkey.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VPN Mentor disclosed CVE-2018-10562 as a GPON command-execution vulnerability. The content provides POST payloads abusing the router diagnostic endpoint to execute wget commands and download Muhstik components. | Hajime updated and began to infect GPON-related devices.
VPN Mentor disclosed two vulnerabilities of GPON home routers on 2018-05-01: CVE-2018-10561 authentication bypass and CVE-2018-10562 command execution vulnerabilities. From 2018-05-02 through 2018-05-10, five botnet families were observed using the GPON exploit. | Hajime updated and began to infect GPON-related devices.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
“Eventually attackers, including the Hajime botnet, exploited this vulnerability in the wild.” | CVE-2017-20149, also known as Chimay Red... affected the HTTP interface of Mikrotik routers... attackers, including the Hajime botnet, exploited this vulnerability in the wild... Greynoise continues to see active scanning for the vulnerability.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
“Find a MikroTik device by checking if the target port is open on port 8291, if this port is open,the other common web ports (80,81,82,8080,8081,8082,8089,8181,8880) will be probed next.”
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
researchers identified more than 1,350 command-and-control servers spread across 98 providers in 14 countries.
The sample represents a brand new P2P botnet implemented based on the DHT protocol... join the Mozi P2P network to become the new Mozi Bot node
Hajime utilizes a decentralized peer-to-peer network to issue commands to its bots. This makes it much harder to locate the Command-and-Control (C2) server for a takedown.
“Once the vulnerability is successfully exploited, Hajime will be downloaded and executed.”
This worm builds a huge P2P botnet... By announcing on the DHT network with a peer id similar to that day’s identifier of the configuration file we were able to be the “nearest” node and collected requests from almost every infected device... All of them were requesting Hajime config.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT-focused botnet operating through C2 infrastructure and abusing compromised routers and embedded devices.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
Botnet referenced as already associated with exploitation of a Xiongmai vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.