Kaiji

First seen
2020-04-25 00:00:00
Malware type
ddos
Family
Malware family
Last IoC activity
2026-07-22 00:16:32
Profile updated
2026-07-07 12:59:11

Context

Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.

Detection coverage

  • 1 YARA rules

Detection rules

  • RUSSIANPANDA_Kaiji_Ares (yara-rule)

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • blog.lumen.com — Chaos Is A Go Based Swiss Army Knife Of Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Kaiji (report)
  • intezer.com — Kaiji New Chinese Linux Malware Turning To Golang (report)
  • Trend Micro — Xorddos Kaiji Botnet Malware Variants Target Exposed Docker Servers (report)
  • elastic.co — Betting On Bots (report)
  • bitdefender.com — Kaiji New Strain Iot Malware Seizing Control Launching Ddos Attacks (report)
  • ibm.com — Wmdzowk6 (report)

External references