Advent of Configuration Extraction – Part 1: Pipeline Overview – First Steps with Kaiji Configuration Unboxing
ID: 0f702a01-f408-58e4-9cad-bfdf6a3a2782
STIX ID: report--0f702a01-f408-58e4-9cad-bfdf6a3a2782
Feed Name: Sekoia.io Blog
Date Published: 2025-12-01
Date Updated: 2026-04-29
Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR
This post introduces Sekoia TDR's Assemblyline ConfigExtractor pipeline and demonstrates extracting C2 configuration from the Go-based Kaiji IoT botnet. It explains static-analysis findings (Base64-encoded C2:Port strings, a distinctive "use ParseCertificate" marker), the extractor implementation (FLOSS string extraction, regex decoding, YARA matching, MACO mapping), and notes Kaiji variants (including Chaos) that incorporate vulnerability exploitation (CVE-2024-7954, CVE-2023-1389) and expanded capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
