logo

Masjesu botnet targets IoT devices while evading high-profile networks

ID: dd589889-a3d8-5b2f-ada9-ee4029f622b8

STIX ID: report--dd589889-a3d8-5b2f-ada9-ee4029f622b8

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Masjesu is a stealthy, commercially-run IoT botnet active since 2023 that conducts DDoS-for-hire operations by infecting routers and embedded devices across multiple architectures. It employs XOR-based obfuscation, persistence mechanisms (renamed binaries, cron jobs, daemonization), process spoofing, and kills competing services; propagates by scanning and exploiting known router/GPON/Netgear flaws while deliberately avoiding high-profile IP ranges (e.g., DoD). Operators advertise access on Telegram, and the botnet has launched floods up to ~290 Gbps with geographically diverse traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.