How to Set Up Runtime Protection Against Malware Like Kaiji
ID: f9dc794e-b73a-519a-abb0-702cf5991dc4
STIX ID: report--f9dc794e-b73a-519a-abb0-702cf5991dc4
Feed Name: Aqua Security Blog
Threat Score
This report describes the Kaiji malware campaign targeting Linux servers and IoT devices, highlighting its persistence and stealth techniques—such as planting startup scripts, intercepting administrative commands, and hiding processes/files—to survive reboots and evade casual inspection; it also provides guidance on detecting and blocking Kaiji at runtime using Aqua Runtime Protection policies (e.g., blocking fileless execution, drift prevention, and enforcement modes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
