P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring) — Threadlinqs Intelligence
As of 2026-06-10, P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring) is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0752 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
360 Netlab's continuous-monitoring review profiles five active peer-to-peer (P2P) botnet families — Pink, Hajime, Mozi, FritzFrog, and Panchan. Their decentralized command-and-control (no single C2
This intelligence consolidates 360 Netlab's ongoing tracking of the peer-to-peer (P2P) botnet ecosystem alongside the original family-specific research from 360 Netlab, Akamai, NSFOCUS, Kaspersky, and others. P2P botnets replace the classic centralized command-and-control (C2) server with a decentralized overlay network in which every infected node can relay commands, distribute payloads, and propagate the worm. Because there is no single point of failure, sinkholing or seizing one server does not dismantle the botnet, and operators can keep pushing signed configuration updates across the mesh. 360 Netlab tracks these networks with four strategies: active probing (sending crafted probe messages to enumerate peers), traversing recent-communications/peer lists held by DHT nodes, node-heartbeat injection (inserting forged nodes that maintain heartbeats on peer lists), and a 'wait and see' approach that forges DHT identities closer to a target key to capture incoming peer-discovery requests.
Pink is the largest P2P botnet tracked, having infected more than 1.6 million devices (the great majority in China), primarily MIPS-based fiber/broadband routers. NSFOCUS attributed initial compromise to a zero-day against specific broadband-device brands. Pink is a hybrid: it uses a central C2 for time-sensitive commands, a P2P layer for non-urgent instructions, and third-party services (a project hidden on GitHub or Baidu Tieba, plus hard-coded domains delivered over DNS-over-HTTPS, DoH) to bootstrap configuration. It uniquely re-flashes the original firmware of the fiber router after infection — embedding the downloader C2 and a supporting bootloader in the rewritten firmware — to achieve near-permanent control. Pink's purpose is DDoS and HTTP ad injection. A pronounced decline began around 2022-07-12 (dropping to roughly 20,000 daily active nodes), attributed by 360 Netlab to a nationwide cleanup effort by device vendors and C2-blocking actions in late August 2022.
Hajime emerged in October 2016 (months after Mirai). It builds its overlay as a trackerless torrent on top of the public BitTorrent DHT using dynamic info_hashes that rotate daily, and exchanges data with peers over uTorrent's Micro Transport Protocol (uTP). All BitTorrent communications are signed and encrypted using RC4 with private/public keys. Hajime self-propagates via three attack methods: TR-069/CWPM exploitation (the NewNTPServer command-injection vector, typically TCP 7547, sometimes 5555), Telnet default-password attacks, and the Arris cable-modem 'password of the day' attack. The config file carries a signed list of per-architecture 'atk' (attack) and '.i' (infection) modules; nodes search for `.i.xxx` and `atk.xxx` binaries by CPU type. After infection Hajime blocks ports 23, 7547, 5555, and 5358 to lock out Mirai and other competitors, and opens UDP/1457 plus a random high port for DHT/uTP. Infections skew heavily toward MIPS devices, with Iran historically the top country.
Mozi, first identified by 360 Netlab on 2019-12-03, is a DHT-based botnet named after its propagation samples Mozi.m and Mozi.a. It uses a BitTorrent-like DHT to record peer contact information and syncs encrypted configuration files across nodes. Mozi reuses Gafgyt code for common functions (single-instance enforcement, process-name modification, ACL modification) and Gafgyt attack code (HTTP/TCP/UDP DDoS), and later added a crypto-mining component. It spreads through weak/default Telnet credentials and unpatched CVEs including CVE-2017-17215 (Huawei HG532), CVE-2018-10561/CVE-2018-10562 (GPON home routers), and CVE-2014-8361 (Realtek SDK miniigd UPnP). Targets expanded to Netgear, Huawei, and ZTE network gateways; infections concentrated in India and China.
FritzFrog, first observed 2020-01-09, is a Golang, modular, multi-threaded, fileless worm with a completely proprietary P2P protocol written from scratch (no μTP/known protocol). It brute-forces SSH credentials against government, educat
Weaknesses (CWE)
CWE-1392, CWE-307, CWE-78, CWE-798
Target sectors: education, government, healthcare, financial, telecommunications, transportation, consumer-iot
Target regions: China, India, Iran, North America, Europe, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2017-17215, CVE-2018-10561, CVE-2018-10562, CVE-2014-8361, T1584, T1190, T1078, T1133, T1059, T1098, T1543, T1542, T1036, T1027