Security researchers say they have discovered yet another type of malware specifically designed to infect Linux-based servers and smart Internet of Things (IoT) devices, then abuse those systems to launch DDoS attacks. Dubbed Kaiji, this new malware was spotted last week by a security researcher who goes by the name MalwareMustDie.

The malware is very different from other strains of IoT malware, mainly because it is written in the Go programming language, instead of C or C++, the two languages in which most IoT malware is coded these days.
Go malware is rare, not because it is not effective, but because there are already so many C or C++ projects freely available on GitHub and intrusion forums that making creating an IoT botnet a simple operation.
Very few IoT malware writers spend their time coding a botnet from scratch these days. In fact, the vast majority of IoT botnets are a combination of different parts and modules taken from multiple strains, combined with new variations of the same old botnet codebases.
“The IoT botnet ecosystem is relatively well documented by security experts,” said Paul Litvak, a malware analyst at Intezer, who analyzed the code in a report published yesterday.
“It’s not often you see botnet tools written from scratch.”
According to Litvak and MalwareMustDie, Kaiji has already been detected on systems, slowly spreading around the world, creating new victims.
The Intezer researcher says that for now, the botnet is unable to use exploits to infect unpatched devices. Instead, the Kaiji botnet is performing brute-force attacks against IoT devices and Linux servers that have left their SSH port exposed to the internet.
It only targets the “root” account, Litvak says. The reason is that the botnet needs root access on infected devices to manipulate raw network for the DDoS attacks they want to carry out and the other functions they want to perform.
Once it gains access to a device's root account, Kaiji will use the device in three ways. First, for DDoS. Second, to perform more SSH brute-force attacks against other devices. Third, it randomly steals local SSH keys and spreads to other devices that the account administrator has previously managed.
Litvak says that the botnet, despite having the ability to launch six different types of DDoS attacks, was clearly a work in progress.
But while this botnet wasn't a threat now, it doesn't mean it won't be in the future. Both MalwareMustDie and Litvak are now monitoring its evolution.
The two researchers also agree that the botnet appears to be the work of a Chinese programmer, as many functions in the code, while written in English, were simple translations of Chinese terms.
