HinataBot

First seen
2023-01-01 00:00:00
Malware type
ddos, botnet
Family
Malware family
Last IoC activity
2026-07-03 14:23:13
Profile updated
2026-07-07 14:25:48

Targeted industries: technology-and-telecommunications energy-and-utilities

Context

HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.

Exploited vulnerabilities

  • CVE-2014-8361 (vulnerability)
  • CVE-2017-17215 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Hinata Bot (report)
  • akamai.com — Hinatabot Uncovering New Golang Ddos Botnet (report)

External references