Surprised about the lack of commentary about Hajime here on HN. This article was interesting. Is the author really whitehat? Is it just one person? Is it a state actor? Are they biding their time for a malicious payload?
Maybe it would be more believably whitehat if some fraction of infections just closed down vulnerable ports and disconnected from c&c or removed themselves.
https://news.ycombinator.com/item?id=14201908