logo

Inside the Masjesu IoT Botnet’s 3-Year Stealth Reign

ID: ce5a57e3-1bf8-5415-b52c-2affb064e415

STIX ID: report--ce5a57e3-1bf8-5415-b52c-2affb064e415

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Masjesu is a commercially operated IoT botnet active since early 2023 that emphasizes stealth and long-term persistence. It targets a wide range of architectures (i386, MIPS, ARM, AMD64), exploits known vulnerabilities in devices from vendors like D-Link, GPON and Netgear, uses XOR-based string/config obfuscation, and communicates with resilient C2 infrastructure (multiple domains and fallback IPs). The bot supports diverse DDoS methods (TCP/UDP/HTTP floods, VSE, RDP/GRE, OSPF/ICMP/IGMP), uses the distinctive user-agent "masjesu," and is marketed via encrypted channels as a DDoS-for-hire service; recommended defenses include patching edge devices, monitoring for the "masjesu" user-agent, and behavioral detection of XOR-encrypted payloads and anomalous connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.