Inside the Masjesu IoT Botnet’s 3-Year Stealth Reign
ID: ce5a57e3-1bf8-5415-b52c-2affb064e415
STIX ID: report--ce5a57e3-1bf8-5415-b52c-2affb064e415
Feed Name: securityonline.info
Masjesu is a commercially operated IoT botnet active since early 2023 that emphasizes stealth and long-term persistence. It targets a wide range of architectures (i386, MIPS, ARM, AMD64), exploits known vulnerabilities in devices from vendors like D-Link, GPON and Netgear, uses XOR-based string/config obfuscation, and communicates with resilient C2 infrastructure (multiple domains and fallback IPs). The bot supports diverse DDoS methods (TCP/UDP/HTTP floods, VSE, RDP/GRE, OSPF/ICMP/IGMP), uses the distinctive user-agent "masjesu," and is marketed via encrypted channels as a DDoS-for-hire service; recommended defenses include patching edge devices, monitoring for the "masjesu" user-agent, and behavioral detection of XOR-encrypted payloads and anomalous connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
