Vigilante Hacker Uses Hajime Malware to Fight with Mirai Botnets











Hajime, an IoT malware strain discovered last October, appears to be the work of a vigilante who has set out to take over and neutralize as many smart devices as possible before other botnets like Mirai can get ahold of them.


While Hajime was first observed last year, it only recently became apparent to researchers that the author of this malware had no intention of using infected devices for evil.


When it was discovered last October, Hajime only came with a self-replication module that allowed it to spread from IoT device to IoT device via open and unsecured Telnet ports.




Related  Hackers Attacked Tesco Bank And Hacked Over 40,000 Customer’s Accounts


At the time, researchers didn’t spot a DDoS module but that wasn’t something noteworthy, as they just discovered this new threat, and to all intent and purpose, they considered Hajime an in-dev malware, one that could add DDoS capabilities once it matures.


Hajime matures but never adds a DDoS module


That maturation didn’t take place, or at least not in the way researchers expected.


The initial Rapidity Networks report that unveiled Hajime’s presence to the world also detailed some bugs. According to Symantec researcher Waylon Grange, Hajime’s author appears to have read the report and fixed those bugs, but that was it.


[irp]


The malware’s author didn’t add a DDoS feature, didn’t use his botnet to relay malicious traffic, or any other intrusive operation.


For the past six months, Hajime has been using its self-replication module to fight with Mirai and other IoT botnet for control over IoT devices.


Hajime used to secure IoT devices(Vigilante)


According to Grange, once Hajime infects a device it blocks access to ports 23, 7547, 5555, and 5358, which are all ports that have been exploited in the past by IoT malware.


After that, Hajime also contacts its command and control server and returns a cryptographically-signed message every ten minutes. The message, which is displayed on the device’s terminal, reads as follows:


[irp]

Just a white hat, securing some systems.
Important messages will be signed like this!
Hajime Author.
Contact CLOSED
Stay sharp!



  • The Reference By Latest Hacking News.