Masjesu botnet targets IoT devices while evading high-profile networks
ID: dd589889-a3d8-5b2f-ada9-ee4029f622b8
STIX ID: report--dd589889-a3d8-5b2f-ada9-ee4029f622b8
Feed Name: Security Affairs
Masjesu is a stealthy, commercially-run IoT botnet active since 2023 that conducts DDoS-for-hire operations by infecting routers and embedded devices across multiple architectures. It employs XOR-based obfuscation, persistence mechanisms (renamed binaries, cron jobs, daemonization), process spoofing, and kills competing services; propagates by scanning and exploiting known router/GPON/Netgear flaws while deliberately avoiding high-profile IP ranges (e.g., DoD). Operators advertise access on Telegram, and the botnet has launched floods up to ~290 Gbps with geographically diverse traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
