Researchers reported that Kaiji and XORDDoS operators were actively compromising Linux infrastructure to expand botnets used for distributed denial-of-service attacks. Trend Micro observed both malware families targeting exposed Docker servers through the unauthenticated Docker API on port 2375: XORDDoS enumerated running containers on vulnerable hosts and executed commands inside each one to download and launch its payload, while Kaiji scanned for exposed Docker instances, validated targets, and deployed a rogue ARM container that fetched and ran the malware. The activity showed two distinct propagation models aimed at the same weakly secured container environments.
Separate analysis of Kaiji found the malware was a Golang-based Linux and IoT botnet with assessed Chinese origins, built from scratch rather than derived from Mirai or BillGates. Researchers said Kaiji also spread through SSH brute forcing, targeted the root account, installed itself under disguised filenames, and supported DDoS functions, shell command execution, C2 replacement, self-deletion, and Linux persistence. It also attempted lateral movement by abusing local SSH keys and IP addresses recovered from bash history and known-hosts data, although researchers assessed the operation as relatively immature because its infrastructure was short-lived and parts of the code appeared unfinished.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers identified a new botnet campaign named Kaiji in late April, assessing it as a Linux server and IoT botnet with definitive Chinese origins that spreads via SSH brute forcing. The malware was described as written from scratch in Golang rather than derived from Mirai or BillGates.
Trend Micro reported new variants of both XORDDoS and Kaiji targeting internet-exposed Docker API port 2375. In the observed activity, XORDDoS infected existing containers by executing commands in each one, while Kaiji deployed a rogue ARM container to download and run its payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourceblog.trendmicro.com
Open sourceintezer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.