Skip to main content

Internet of Things malware Hajime is creating a botnet from 300,000 devices

hajime iot botnet internet of things 1200x0
For many people, there is a growing concern over smart devices becoming connected. While smart devices make day-to-day life more convenient, there is an underlying risk of malware attacking and making use of these devices. One such example is Hajime, an Internet of Things (IoT) malware that is creating a peer-to-peer botnet. Already it has compromised almost 300,000 devices.

Kaspersky Lab recently published its research into Hajime and its unknown end goal. So far, this malware has focused its attention on DVRs, webcams, and routers, but it is capable of attacking any device on the internet. Using a brute-force attack on device passwords, Hajime infects the device, and then conceals itself from the victim. Compromised devices can then be used by Hajime’s creator without the victim’s knowledge.

Related Videos

While a majority of these compromised devices are located in Iran, Vietnam, and Brazil, Kaspersky Lab suggests that IoT owners change their passwords to something more difficult to guess through brute force. Additionally, owners should update their firmware if needed.

First signs of Hajime appeared in October 2016 and it has since developed new ways of spreading. Instead of containing attack code, this malware only contains a propagation module. As it takes over a device, it adds it to an existing peer-to-peer botnet. This network of compromised devices is then used for spam or DDoS attacks.

There are a few networks that Hajime has avoided. These include General Electric, Hewlett-Packard, the U.S. Postal Service, the United States Department of Defense, and a few private networks.

“The most intriguing thing about Hajime is its purpose,” said Konstantin Zykov, senior security researcher at Kaspersky Lab. “While the botnet is getting bigger and bigger, its objective remains unknown. We have not seen its traces in any type of attack or additional malicious activity.”

Full details about this research are available on the firm’s SecureList blog.

Editors' Recommendations

Garmin Connect IQ watch users can now control their Samsung SmartThings-powered devices
Garmin Vivoactive HR

Garmin kicked off its Connect IQ Developer Summit in its home state of Kansas this week, and one of the more noteworthy announcements to come out of the conference about the company's new partnership with Samsung SmartThings automation.

A just-released SmartThings app has been made available for the 5 million Connect IQ devices in the wild, allowing users to control various smart devices in their home, from televisions to locks and thermostats. You can also execute automated routines to, say, turn on your coffee maker and lights when you wake up in the morning.

Read more
New ‘BrickerBot’ malware attack kills unsecured Internet of Things devices
microsoft security intelligence report 2016 online piracy

The Internet of Things (IoT) is at the heart of many modern technology devices, not the least of which are the increasingly popular smart home components that unlock our doors and control our heating and lighting. The security of IoT devices is, therefore, paramount if these increasingly ubiquitous devices are going to bring more benefit than cost.

Unfortunately, IoT has been the source of significant malware attacks in recent months, including the distributed denial of service (DDoS) attack that took down a large swatch of the internet in October 2016. Now, a new piece of malware, dubbed BrickerBot, is in the wild and targeting IoT device running the open-source Linux operating system, as Readwrite reports.

Read more
What if all the ‘things’ in the Internet of Things spoke the same language?
An Internet of Things simulation.

Imagine if you had to choose banks, grocery stores, and doctors in your city based on the languages they recognized. That restriction would be more than irksome. You might miss out on wonderful new stores or be unable to use a medical specialist who was the only one in town who could help with a specific problem. Avoiding a similar troublesome limitation is the force behind a big push for a standard connectivity language for the Internet of Things.

The Open Connectivity Foundation (OCF), a new organization formed last year with some, but not all, of the biggest IoT players, is making progress with a standard communications platform, Fast Company reported. With all the connectivity and control devices, hubs, platforms, and interfaces for smart homes alone, never mind industrial, transportation, shipping, and other IoT applications, the need for more open connectivity is increasingly apparent. If you are attracted by the feature set in a specific outdoor security camera, why should you have to make sure it can "talk" to your home thermostat and your new car's geo-fencing alert system?

Read more