Hajime is a Linux-based IoT malware family and worm-like botnet first identified in 2016. It targets embedded devices such as routers, cameras, DVRs, and similar internet-exposed systems, and is widely noted as a Mirai-era botnet that differs from typical centralized IoT malware by using a decentralized peer-to-peer architecture. Hajime has been described as modular, with separate propagation and execution components, and has been observed using DHT-based peer discovery and synchronization, uTP over UDP for inter-node communications, RC4 session encryption, Curve25519-based key exchange, and ED25519 signatures to authenticate synchronized files and configuration data.
Its primary observed behavior is self-propagation. Hajime spreads through brute-forcing weak or default Telnet credentials and has also incorporated exploitation of vulnerabilities in exposed network devices, including TR-069-related remote code execution paths and later GPON router flaws. Reports also describe targeted login logic for specific device banners and architecture-aware payload delivery across multiple embedded CPU families, especially MIPS variants. The malware synchronizes modules across peers and has shown continued evolution through botnet updates and added architecture support.
Unlike many IoT botnets, Hajime has not been conclusively observed deploying distributed denial-of-service or other overt attack modules in the wild. Multiple analyses state that only its spreading functionality has been consistently observed. It is also known for blocking access to ports commonly abused by competing IoT malware and for displaying a message claiming to be a white-hat effort securing devices, leading to frequent comparisons with Linux.Wifatch and occasional characterization as a vigilante botnet. Despite that messaging, Hajime remains unauthorized malware that compromises devices and enrolls them into a resilient botnet.
Hajime has infected large numbers of devices globally, with reporting placing the botnet in the hundreds of thousands at its peak. Iran has repeatedly appeared as a leading concentration of infections, with substantial activity also observed in Brazil, Vietnam, Russia, Turkey, India, Pakistan, Italy, and Taiwan. Its peer-to-peer design and cryptographic controls have made tracking and takedown more difficult than for conventional IoT botnets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Gigabit-capable Passive Optical Network (GPON) routers manufactured by DASAN Zhone Solutions have been found vulnerable to an authentication bypass (CVE-2018-10561) and a root-RCE (CVE-2018-10562) flaws that eventually allow remote attackers to take full control of the device. | Hajime Botnet — Another infamous IoT botnet, Hajime, has also been found adding GPON exploit to its code to target hundreds of thousands of home routers.
Gigabit-capable Passive Optical Network (GPON) routers manufactured by DASAN Zhone Solutions have been found vulnerable to an authentication bypass (CVE-2018-10561) and a root-RCE (CVE-2018-10562) flaws that eventually allow remote attackers to take full control of the device. | Hajime Botnet — Another infamous IoT botnet, Hajime, has also been found adding GPON exploit to its code to target hundreds of thousands of home routers.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
“Eventually attackers, including the Hajime botnet, exploited this vulnerability in the wild.” | CVE-2017-20149, also known as Chimay Red... affected the HTTP interface of Mikrotik routers... attackers, including the Hajime botnet, exploited this vulnerability in the wild... Greynoise continues to see active scanning for the vulnerability.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
IoT malware scans the Internet for IoT devices that use default or weak usernames and passwords.
Once the attack successfully passes the authentication stage, the first 52 bytes of the victim’s echo binary are read... The victim’s echo ELF header is then compared against a predefined array, containing the Hajime stub downloader binaries for different architectures.
researchers identified more than 1,350 command-and-control servers spread across 98 providers in 14 countries.
The sample represents a brand new P2P botnet implemented based on the DHT protocol... join the Mozi P2P network to become the new Mozi Bot node
Hajime utilizes a decentralized peer-to-peer network to issue commands to its bots. This makes it much harder to locate the Command-and-Control (C2) server for a takedown.
And once they do, malicious binaries are downloaded and executed... One of these commands instruct bots to download and execute binaries, internally called 'modules'.
This worm builds a huge P2P botnet... By announcing on the DHT network with a peer id similar to that day’s identifier of the configuration file we were able to be the “nearest” node and collected requests from almost every infected device... All of them were requesting Hajime config.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware observed among families associated with the mapped C2 infrastructure.
An IoT-focused botnet operating through C2 infrastructure and abusing compromised routers and embedded devices.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
Botnet referenced as already associated with exploitation of a Xiongmai vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.