A botnet (Hajime) that was discovered at the end of last year has grown to a massive size in recent weeks, but security researchers cannot understand why, as they cannot figure out what it does.
The malicious software (malware) named Hajime was found last October, around the same time the infamous and now notorious botnet Mirai was used in attacks against the American internet.
The Hajime botnet has so far infected 300,000 devices connected to the internet (digital video cameras, cameras and routers) and appears to carefully target specific networks, avoiding devices that belong to American government services. Like Mirai, the malware attacks devices that have weak or default passwords and usernames (often “admin” or “root”).
What makes the malicious software Hajime very different is that it closes certain ports on the firewall and opens several others to create a peer-to-peer management and control structure.
However, to date no one is sure what the botnet does or who is behind it.
"The most interesting thing about Hajime is its purpose," Kaspersky security researchers said in a blog post, adding that its purpose "remains unknown."
“We have not seen it being used in any kind of attack or malicious activity”, the researchers said.
All signs point to a white hat hacker, who has taken on to “secure some systems”, according to a note he leaves on each system the botnet infects.
But any botnet – even those that were created with good intentions – can be used for malicious purposes, either by the botnet’s owner or by someone else who manages to gain access.
A map showing the geographic sources of the Hajime infection. (Image: Radware)
Radware researchers said on Wednesday that the “flexible and scalable nature” of the botnet could be used for malicious purposes, such as executing DDoS attacks, spreading malicious software or massive real-time streaming surveillance from web cameras.
Researchers also report that a vulnerability that was patched recently in Hajime could allow a hacker to take control of the botnet.
“A botnet that large with such flexibility would attract the attention of competing hackers, so I think it is very likely they will try to take control and assume the botnet’s commands.”
“The vulnerability has been closed by the developer, but it shows that malicious software can contain vulnerable points” say the researchers.
