Kaiten, also known as Tsunami, is a C-based, IRC-controlled botnet malware family primarily associated with Linux systems and distributed denial-of-service attacks. Infected hosts connect to IRC command-and-control infrastructure and receive operator instructions, allowing compromised servers and embedded devices to participate in coordinated attacks. Its code has been reused in numerous variants and derivative IRC bots.
Kaiten variants have been deployed against internet-exposed Linux servers, IoT devices, routers, and container environments. Distribution campaigns have installed Kaiten alongside cryptocurrency miners on exposed Docker infrastructure, while the Momentum botnet has distributed Kaiten variants through exploitation of vulnerable routers and web services. Historical infections also involved Microsoft SQL Server installations with blank default passwords. Modified Kaiten variants have incorporated default credentials for industrial and operational-technology products, including Schneider Electric Modicon, Siemens SIMATIC, Emerson, and Sierra Wireless devices.
CAPSAICIN, a Kaiten variant, has been distributed through command-execution vulnerabilities in D-Link router HNAP interfaces. It supports multiple processor architectures, terminates competing botnet processes, reports operating-system information to its command-and-control server, and accepts IRC instructions for DDoS activity. TeamTNT has also used Kaiten-derived IRC bots in Linux and cloud-focused operations, including Kubernetes compromises. Cryptocurrency mining, credential theft, and lateral movement in these campaigns are performed by accompanying tools and are not intrinsic capabilities established for Kaiten itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The IRC bot, also written in C, is based on another famous IRC bot called Kaiten.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
In a UDP-BYPASS attack, Momentum floods the target host by constructing and unloading a legitimate UDP payload on a specific port.
The IRC protocol is the main method of communication with the command and control (C&C) servers.
Tsunami/Kaiten... mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC... ShellBot... It is an IRC bot with remote shell, scanning, and DDoS functionality.
Apart from DoS attacks, we found that Momentum is also capable of other actions: opening a proxy on a port on a specified IP...
The script also installs two free, open-source tools available from GitHub, the network scanning tool masscan ... and the banner-grabbing, deprecated Zgrab ... 3. Downloads a shell script called setup_xmr.sh from the TeamTNT C&C server
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
I also discovered they support several new DDoS methods previously unused by Mirai variants.
94 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as competing malware killed by the sample. It is described as a classic IRC-based DDoS bot/tool present in the IoT malware ecosystem.
Parent botnet family of CAPSAICIN. The reference identifies this lineage but does not separately analyze Kaiten's capabilities or activity.
A botnet variant observed using default OT product credentials, mixed with general IoT passwords, to target exposed devices including OT/ICS equipment.
Kaiten is a DDoS botnet malware family targeting Linux systems, known for its use in large-scale denial-of-service attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.