logo

Advent of Configuration Extraction – Part 1: Pipeline Overview – First Steps with Kaiji Configuration Unboxing

ID: 0f702a01-f408-58e4-9cad-bfdf6a3a2782

STIX ID: report--0f702a01-f408-58e4-9cad-bfdf6a3a2782

Feed Name: Sekoia.io Blog

Threat Score
60/100

Date Published: 2025-12-01

Date Updated: 2026-04-29

Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR

...
...

This post introduces Sekoia TDR's Assemblyline ConfigExtractor pipeline and demonstrates extracting C2 configuration from the Go-based Kaiji IoT botnet. It explains static-analysis findings (Base64-encoded C2:Port strings, a distinctive "use ParseCertificate" marker), the extractor implementation (FLOSS string extraction, regex decoding, YARA matching, MACO mapping), and notes Kaiji variants (including Chaos) that incorporate vulnerability exploitation (CVE-2024-7954, CVE-2023-1389) and expanded capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.