Hakai is an Internet-of-Things botnet derived from the leaked Gafgyt codebase, also known as Bashlite. It compromises routers and other embedded devices to recruit them into a distributed denial-of-service botnet. Its propagation combines Telnet scanning and credential brute forcing against default or weak passwords with exploitation of remote command-execution vulnerabilities.
Hakai exploits vulnerabilities affecting Huawei routers, including CVE-2017-17215; D-Link devices exposing the Home Network Administration Protocol, including CVE-2015-2051; and devices using vulnerable Realtek SDK versions, including CVE-2014-8361. Exploit-bearing samples also target Netgear and Eir routers, surveillance recording devices, and vulnerable ThinkPHP installations. Later samples added an operating-system command-injection exploit against D-Link DSL-2750B routers. Infected devices communicate with command-and-control infrastructure, while payload-hosting infrastructure supplies malware for additional infections.
Hakai activity has included substantial growth in Latin America. Related variants named Kenjiro and Izuku have also circulated. Separate Bashlite campaigns have used embedded droppers designed to retrieve and execute Hakai.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Home Network Administration Protocol (HNAP) SOAPAction-header command execution vulnerability that works on certain D-Link devices.
“The first ever Hakai exploit attack was seen on July 21,” Anubhav told ZDNet. That exploit leveraged CVE-2017-17215, a vulnerability affecting Huawei HG352 routers, the researcher told us. | Tracked by the infosec community as Hakai ... this botnet was first spotted in June by security researchers from NewSky Security.
The D-Link DSL-2750B remote code execution example contains the header User-Agent: Hakai/2.0.
The D-Link DSL-2750B remote code execution example contains the header User-Agent: Hakai/2.0.
The D-Link DSL-2750B remote code execution example contains the header User-Agent: Hakai/2.0.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
In May 2018, the Omni botnet, a variant of Mirai, was found exploiting two vulnerabilities affecting Dasan GPON routers - CVE-2018-10561 (authentication bypass) and CVE-2018-1562/10562 (command injection). The two vulnerabilities used in conjunction allow the execution of commands sent by an unauthenticated remote attacker to a vulnerable device.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware based on Bashlite code that the analyzed Bashlite samples attempted to download and execute as an additional payload.
Bashlite-derived botnet malware previously observed targeting routers. The analyzed Bashlite infection chain includes a dropper intended to download and execute Hakai on compromised devices, although the referenced download URL was no longer accessible.
Appears only as a user-agent identifier in a sample explicitly attributed to Zerobot. The reference does not establish a separate Hakai infection or exploit set.
Named botnet identifier appearing in a D-Link DSL-2750B exploitation sample. The report states that samples exploiting this vulnerability also contained exploits for several Realtek, D-Link, Huawei, Zyxel, and ThinkPHP vulnerabilities; it does not provide a separate family analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.