Kaiji Malware Analysis Details Linux Persistence and Evasion Techniques

· Original article ↗

Summary

Aqua researchers analyzed a Kaiji infection on a weak-password SSH honeypot, documenting its DDoS and proxy capabilities, persistence and evasion methods, and campaign infrastructure, including a server with more than 70,000 collective malware downloads.

Key points

  • Attackers infected an Aqua honeypot through exposed SSH access protected by a weak password; the researchers stopped a subsequent attack and analyzed the artifacts.
  • The Go-based Kaiji payload supports more than 24 DDoS attack vectors, SOCKS5 and HTTP proxying, and command-and-control over HTTP, HTTPS, and WebSocket.
  • Kaiji persists through systemd and SysV services, cron jobs, and login-shell execution, placing copies of its payload in multiple system directories.
  • The malware weakens SELinux protections and hides activity by bind-mounting over its /proc entry and filtering malware-related results from common system commands.
  • The analyzed campaign used the C2 subdomain else.su6s.su and downloaded payloads from 195.177.94.29:26154; the article dates the current infrastructure to August–September 2025.
  • Aqua’s four-day collection from the download server showed more than 70,000 collective downloads across malware files, with multiple Kaiji architecture variants.
  • The article recommends runtime monitoring for unusual network bindings and proxy activity, and policies to block container drift and fileless execution.

Article Details

Attack Vectors
  • Attackers accessed Aqua's honeypot through an exposed, misconfigured SSH service with a weak password and infected it with Kaiji.
  • According to Santander's security research team, attackers also hid a backdoor in CVE-2024-6387 proof-of-concept code targeting security researchers; running the code could infect a server with Kaiji. The article does not report exploitation of the vulnerability itself.
  • The main Kaiji payload was downloaded from an HTTP file server at 195.177.94.29:26154.
Defensive Notes
  • Aqua says its Runtime Protection can detect unusual network bindings and unauthorized proxy activity associated with Kaiji.
  • Aqua says runtime policies in Aqua Platform can block container drift and fileless execution.

Indicators of compromise

TypeIndicatorContext
DOMAINsu6s[.]suDomain identified as a C2 server in the attack.
HOSTNAMEelse[.]su6s[.]suSubdomain of the identified C2 domain, reported to resolve to 198.251.81.61.
IPV4195[.]177[.]94[.]29HTTP file server, on port 26154, from which the main Kaiji payload was downloaded.
IPV4198[.]251[.]81[.]61IP address reported for the subdomain of the identified Kaiji C2 domain.
IPV445[.]12[.]1[.]19Source of initial access to Aqua's infected honeypot; the article also reports VirusTotal indications linking it to Kaiji attacks.
MD5138ba58259d3c64b34a2b9c5d0b8b178File named linux, identified in the download-server table as an SSHscan worm.
MD522d13a183daf35ab59cefe80c26eed5fKaiji malware file named mips64 on the download server.
MD523c9b408f3695e967237e387a0ee96f3Kaiji malware file named mips on the download server.
MD52964bf18cd6050068e73ccff0c848e48Kaiji malware file named 386 on the download server.
MD53a7ae1ecb3df725b8e5adfef4a2216baKaiji malware file named aarch64 on the download server.
MD575ca8e126c5d0d20bf9dc9002251faeaKaiji malware file named arm6 on the download server.
MD5a073a59ada046057bf1cc5d985d7eea7Kaiji malware file named arm5 on the download server.
MD5b93915ef006606b4720dc566845575a2Malicious file named systeme on the download server; the table labels it Mayday/elknot, but the article says its role was not established.
MD5d432e6694dd34a4b1f329ad10acf802aKaiji malware file named mipsel on the download server.
MD5d607f9dc8f2cdce76dac6eb67e40fa2aKaiji malware file named arm7 on the download server.
MD5d9a7e01b0c65587083fa42bd73783819Kaiji malware file named mips64el on the download server.
MD5fd05b94c016fd2eb7e26c406fa2266d0Main Kaiji payload, listed as amd64 on the download server.

MITRE ATT&CK

CVE

Malware

Vendors

Products

Related Articles