• News/
  • https://www.bleepingcomputer.com/news/security/hajime-botnet-makes-a-comeback-with-massive-scan-for-mikrotik-routers/

Hajime Botnet Makes a Comeback With Massive Scan for MikroTik Routers

BleepingComputer
·
Published Mar 28, 2018
·
Updated

If you've been following the infosec Twitter community for the last few days, you couldn't ignore the constant talk about the massive scans currently taking place online, carried out by a Hajime IoT botnet looking to mass-infect unpatched MikroTik devices. All of the hoopla started on Sunday, March 25, when suspicious scans for port 8291 popped up out of the blue on everyone's honeypots. The new Hajime variant has been scanning wide range of tcp ports since 2018-03-26. Now it scans 80, 81, 82, 8080, 8081, 8082, 8089, 8181, 8291 and 8880. We observe these scanning activities at out honeypots.@360Netlab @chudyPB So the old Hajime botnet is coming back with a new exploit which was published only about 13 days ago ( https://t.co/UEAOTF4DiZ ), it also looks for some old exploits like tr-064 but nothing exciting there. https://t.co/vyIDU7CXpn The scans only continued in the following days, showing no sign of abating, and attracting attention from security researchers from all over the globe. The attention was warranted as the scans weren't something small, and continued at an intensive rate. The first to spot the scans were researchers from Qihoo 360's Netlab team, who said today this Hajime botnet performed over 860,000 scans in the last three days, albeit they couldn't tell how many of these scans were also successful infections. The exploit attackers were trying to use was a vulnerability known as "Chimay Red," a bug that affects MikroTik RouterOS firmware 6.38.4 and earlier, a...

Read full article

Affected Software

3 affected components
Mikrotik RouterOS=6.38.4
Mikrotik RouterOS
Mikrotik RouterOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary concern mentioned in the article regarding the Hajime botnet?

The article discusses the Hajime botnet's resurgence and its extensive scanning activity targeting MikroTik routers.

2

Which specific software is affected by the Hajime botnet's scanning activities?

The affected software includes MikroTik RouterOS, specifically version 6.38.4.

3

What is the potential threat posed by the Hajime botnet to IoT devices?

The Hajime botnet poses a threat of mass infection to vulnerable IoT devices, particularly routers.

4

How are users advised to protect their MikroTik routers from this threat?

Users are advised to ensure their MikroTik routers are updated to the latest version and properly secured.

5

What is the significance of getting involved in the discussions around the Hajime botnet according to the article?

The article emphasizes the importance of community awareness and engagement regarding ongoing security threats like the Hajime botnet.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203