Kaiten, also widely known as Tsunami, is a long-running Linux IRC bot and DDoS malware family that has been extensively reused, modified, and embedded into broader botnet operations targeting internet-exposed devices and servers. It is commonly associated with compromised Linux and IoT systems, including routers, cameras, embedded appliances, cloud workloads, containers, and other Unix-like environments. The malware is typically deployed after opportunistic compromise through exposed services, weak credentials, or exploitation of known vulnerabilities, and then connects to operator-controlled IRC infrastructure to receive commands.
Kaiten’s core role is as an IRC-controlled backdoor with distributed denial-of-service functionality. Variants and descendants support multiple flooding techniques and remote command execution, allowing operators to use infected hosts both for DDoS activity and for general post-compromise control. In multiple observed campaigns, Kaiten-derived bots have also been used alongside cryptominers or other payloads, reflecting its role as a modular secondary payload in Linux intrusion chains.
The family has been repeatedly incorporated into IoT botnets and malware ecosystems adjacent to Mirai and Gafgyt/Bashlite. It has appeared as a competitor process explicitly terminated by other botnets seeking exclusive control of infected devices, indicating its continued prevalence in the Linux/IoT botnet landscape. Modified Kaiten variants have also been observed using default credentials relevant to operational technology and industrial control environments, showing that generic botnet operators have adapted Kaiten-based tooling to opportunistically target exposed OT-capable devices as well.
Kaiten has also served as a code base for later malware. TeamTNT used IRC bots based on Kaiten in cloud- and container-focused campaigns, and other Linux worms and botnets have been described as based on or derived from Kaiten. In Docker-focused intrusions, Kaiten variants have been dropped together with cryptocurrency miners and persistence scripts. Across these uses, the malware remains notable less as a single modern strain than as a durable IRC bot lineage that continues to be repurposed for Linux botnet operations, DDoS attacks, persistence within compromised environments, and remote shell-style control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The IRC bot, also written in C, is based on another famous IRC bot called Kaiten.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
In a UDP-BYPASS attack, Momentum floods the target host by constructing and unloading a legitimate UDP payload on a specific port.
The IRC protocol is the main method of communication with the command and control (C&C) servers.
Tsunami/Kaiten... mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC... ShellBot... It is an IRC bot with remote shell, scanning, and DDoS functionality.
Apart from DoS attacks, we found that Momentum is also capable of other actions: opening a proxy on a port on a specified IP...
The script also installs two free, open-source tools available from GitHub, the network scanning tool masscan ... and the banner-grabbing, deprecated Zgrab ... 3. Downloads a shell script called setup_xmr.sh from the TeamTNT C&C server
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
I also discovered they support several new DDoS methods previously unused by Mirai variants.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as competing malware killed by the sample. It is described as a classic IRC-based DDoS bot/tool present in the IoT malware ecosystem.
A botnet variant observed using default OT product credentials, mixed with general IoT passwords, to target exposed devices including OT/ICS equipment.
Kaiten is a DDoS botnet malware family targeting Linux systems, known for its use in large-scale denial-of-service attacks.
Competing malware that Zerobot attempts to terminate on infected systems during deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.