Hakai is an IoT botnet malware family built on Gafgyt/Bashlite code and used to compromise embedded Linux devices such as routers and similar internet-exposed appliances. It has been observed in campaigns that aggressively combined multiple publicly known remote-code-execution exploits against consumer and small-office networking equipment, DVRs, NVRs, IP cameras, and related devices, with later samples adding exploitation of D-Link DSL-2750B command-injection flaws shortly after public exploit code became available. Hakai has also been associated with brute-force activity against exposed services in broader Bashlite-derived operations.
As a Bashlite-derived bot, Hakai provides backdoor-style remote command execution and is used to conscript infected devices into distributed-denial-of-service infrastructure. Related Bashlite functionality tied to the same ecosystem includes Telnet scanning, credential brute forcing, downloading and executing additional payloads, killing competing malware, and commands intended to bypass mitigation services such as Cloudflare protections. The broader code lineage also supports multiple DDoS attack modes and has been used to deploy additional malware components, including cryptocurrency miners and destructive or bot-killing payloads.
Hakai has been tracked as part of 2018 IoT malware activity that reused and extended publicly available botnet source code rather than introducing novel tradecraft. Its operational focus was rapid mass exploitation of vulnerable embedded devices for botnet growth and post-compromise use in denial-of-service operations. The malware primarily targets Linux-based IoT and network-edge systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-17215 affects Huawei HG532 devices and is listed among the exploits used by the campaigns. The conclusion notes the speed of exploitation in the wild of newly released vulnerabilities.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
CVE-2014-8361 affects different devices using the Realtek SDK with the miniigd daemon and is one of the exploits incorporated into these Mirai/Gafgyt-based IoT malware campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Bashlite-based botnet malware intended as a secondary payload in this infection chain, though the referenced download URL was no longer accessible.
A Gafgyt-based IoT botnet campaign using multiple known exploits, credential brute forcing, and standard flood commands. Newer samples also added a D-Link DSL-2750B OS command injection exploit.
A Gafgyt-based IoT botnet campaign using multiple exploits for propagation, credential brute forcing, and DDoS commands; newer samples added a D-Link DSL-2750B OS command injection exploit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.