Kaiji
- First seen
- 2020-04-25 00:00:00
- Malware type
- ddos
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:16:32
- Profile updated
- 2026-07-07 12:59:11
Context
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.
Detection coverage
- 1 YARA rules
Detection rules
- RUSSIANPANDA_Kaiji_Ares (yara-rule)
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- blog.lumen.com — Chaos Is A Go Based Swiss Army Knife Of Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Kaiji (report)
- intezer.com — Kaiji New Chinese Linux Malware Turning To Golang (report)
- Trend Micro — Xorddos Kaiji Botnet Malware Variants Target Exposed Docker Servers (report)
- elastic.co — Betting On Bots (report)
- bitdefender.com — Kaiji New Strain Iot Malware Seizing Control Launching Ddos Attacks (report)
- ibm.com — Wmdzowk6 (report)