Kaiji Malware Analysis Details Linux Persistence and Evasion Techniques

Summary
Aqua researchers analyzed a Kaiji infection on a weak-password SSH honeypot, documenting its DDoS and proxy capabilities, persistence and evasion methods, and campaign infrastructure, including a server with more than 70,000 collective malware downloads.
Key points
- Attackers infected an Aqua honeypot through exposed SSH access protected by a weak password; the researchers stopped a subsequent attack and analyzed the artifacts.
- The Go-based Kaiji payload supports more than 24 DDoS attack vectors, SOCKS5 and HTTP proxying, and command-and-control over HTTP, HTTPS, and WebSocket.
- Kaiji persists through systemd and SysV services, cron jobs, and login-shell execution, placing copies of its payload in multiple system directories.
- The malware weakens SELinux protections and hides activity by bind-mounting over its /proc entry and filtering malware-related results from common system commands.
- The analyzed campaign used the C2 subdomain else.su6s.su and downloaded payloads from 195.177.94.29:26154; the article dates the current infrastructure to August–September 2025.
- Aqua’s four-day collection from the download server showed more than 70,000 collective downloads across malware files, with multiple Kaiji architecture variants.
- The article recommends runtime monitoring for unusual network bindings and proxy activity, and policies to block container drift and fileless execution.
Article Details
- Attack Vectors
- Attackers accessed Aqua's honeypot through an exposed, misconfigured SSH service with a weak password and infected it with Kaiji.
- According to Santander's security research team, attackers also hid a backdoor in CVE-2024-6387 proof-of-concept code targeting security researchers; running the code could infect a server with Kaiji. The article does not report exploitation of the vulnerability itself.
- The main Kaiji payload was downloaded from an HTTP file server at 195.177.94.29:26154.
- Defensive Notes
- Aqua says its Runtime Protection can detect unusual network bindings and unauthorized proxy activity associated with Kaiji.
- Aqua says runtime policies in Aqua Platform can block container drift and fileless execution.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | su6s[.]su | Domain identified as a C2 server in the attack. |
| HOSTNAME | else[.]su6s[.]su | Subdomain of the identified C2 domain, reported to resolve to 198.251.81.61. |
| IPV4 | 195[.]177[.]94[.]29 | HTTP file server, on port 26154, from which the main Kaiji payload was downloaded. |
| IPV4 | 198[.]251[.]81[.]61 | IP address reported for the subdomain of the identified Kaiji C2 domain. |
| IPV4 | 45[.]12[.]1[.]19 | Source of initial access to Aqua's infected honeypot; the article also reports VirusTotal indications linking it to Kaiji attacks. |
| MD5 | 138ba58259d3c64b34a2b9c5d0b8b178 | File named linux, identified in the download-server table as an SSHscan worm. |
| MD5 | 22d13a183daf35ab59cefe80c26eed5f | Kaiji malware file named mips64 on the download server. |
| MD5 | 23c9b408f3695e967237e387a0ee96f3 | Kaiji malware file named mips on the download server. |
| MD5 | 2964bf18cd6050068e73ccff0c848e48 | Kaiji malware file named 386 on the download server. |
| MD5 | 3a7ae1ecb3df725b8e5adfef4a2216ba | Kaiji malware file named aarch64 on the download server. |
| MD5 | 75ca8e126c5d0d20bf9dc9002251faea | Kaiji malware file named arm6 on the download server. |
| MD5 | a073a59ada046057bf1cc5d985d7eea7 | Kaiji malware file named arm5 on the download server. |
| MD5 | b93915ef006606b4720dc566845575a2 | Malicious file named systeme on the download server; the table labels it Mayday/elknot, but the article says its role was not established. |
| MD5 | d432e6694dd34a4b1f329ad10acf802a | Kaiji malware file named mipsel on the download server. |
| MD5 | d607f9dc8f2cdce76dac6eb67e40fa2a | Kaiji malware file named arm7 on the download server. |
| MD5 | d9a7e01b0c65587083fa42bd73783819 | Kaiji malware file named mips64el on the download server. |
| MD5 | fd05b94c016fd2eb7e26c406fa2266d0 | Main Kaiji payload, listed as amd64 on the download server. |
MITRE ATT&CK
T1053.003 · CronA cron entry runs the /.mod script every minute as root; that script launches a Kaiji payload copy.T1090 · ProxyKaiji includes SOCKS5 and HTTP proxies for relaying traffic through compromised systems.T1105 · Ingress Tool TransferThe main Kaiji payload was downloaded from an attacker-used HTTP file server.T1498 · Network Denial of ServiceKaiji launches volumetric and protocol-specific DDoS attacks against network-accessible targets.T1543.001 · Launch AgentKaiji created and enabled a system service that runs its /boot/system.pub payload copy.T1543.002 · Systemd ServiceKaiji created SysV init scripts, including /etc/init.d/dns-udp4 and /etc/init.d/x11-common, to launch payload copies at startup.T1546.004 · Unix Shell Configuration ModificationA script in /etc/profile.d/ launches the Kaiji payload at login.T1562.001 · Disable or Modify ToolsThe attack generated and installed a SELinux policy module allowing actions previously denied to the system.pub process.T1564.001 · Hidden Files and DirectoriesKaiji's gateway.sh overrides common inspection commands and filters their output to hide malware processes and files.T1564.013 · Bind MountsKaiji bind-mounted /tmp/ over /proc/55 to obscure the malware process's details from inspection.