HinataBot
- First seen
- 2023-01-01 00:00:00
- Malware type
- ddos, botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-03 14:23:13
- Profile updated
- 2026-07-07 14:25:48
Targeted industries: technology-and-telecommunications energy-and-utilities
Context
HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.
Exploited vulnerabilities
- CVE-2014-8361 (vulnerability)
- CVE-2017-17215 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Hinata Bot (report)
- akamai.com — Hinatabot Uncovering New Golang Ddos Botnet (report)