Hakai is an IoT botnet malware family built on Gafgyt/Bashlite code and used to compromise embedded Linux devices such as routers and other internet-connected appliances. It has been observed in campaigns that combined numerous publicly known exploits against vulnerable edge and consumer devices, including routers, DVRs, NVRs, IP cameras, and similar embedded systems. Earlier Hakai samples used a broad exploit set derived from contemporaneous Mirai- and Gafgyt-based campaigns, and later samples added exploitation of D-Link DSL-2750B command-injection exposure shortly after public exploit tooling became available.
Hakai is associated with botnet operations focused on distributed denial-of-service activity. As a Gafgyt-derived family, it is designed to enroll compromised devices into a remotely controlled botnet and execute attack commands issued by operators. Reporting also links Hakai to delivery via droppers used by updated Bashlite activity, indicating overlap in tooling and ecosystem between closely related IoT malware operations.
The malware targets Linux-based embedded platforms and router-class devices exposed to the internet. Observed campaigns relied on exploit-based propagation, and related Bashlite-linked activity tied to Hakai delivery also used Telnet scanning and credential brute forcing against IoT devices. Hakai fits the broader pattern of opportunistic mass exploitation of poorly secured embedded systems for botnet growth and DDoS operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-17215 affects Huawei HG532 devices and is listed among the exploits used by the campaigns. The conclusion notes the speed of exploitation in the wild of newly released vulnerabilities.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
CVE-2014-8361 affects different devices using the Realtek SDK with the miniigd daemon and is one of the exploits incorporated into these Mirai/Gafgyt-based IoT malware campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware based on Bashlite code that the analyzed Bashlite samples attempted to download and execute as an additional payload.
A Bashlite-based botnet malware intended as a secondary payload in this infection chain, though the referenced download URL was no longer accessible.
A Gafgyt-based IoT botnet campaign using multiple known exploits, credential brute forcing, and standard flood commands. Newer samples also added a D-Link DSL-2750B OS command injection exploit.
A Gafgyt-based IoT botnet campaign using multiple exploits for propagation, credential brute forcing, and DDoS commands; newer samples added a D-Link DSL-2750B OS command injection exploit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.