logo

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

ID: fdb29c53-9f40-57b1-9fe9-53bb5f7da0b4

STIX ID: report--fdb29c53-9f40-57b1-9fe9-53bb5f7da0b4

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers from Trellix and NSFOCUS have analyzed Masjesu (aka XorBot), a stealthy IoT botnet marketed on Telegram since 2023 that compromises routers, cameras, DVRs/NVRs and other devices via numerous command-injection and code-execution exploits, establishes persistence by binding a hard-coded TCP port (55988), uses XOR-based obfuscation, self-propagates (including scanning Realtek port 52869), and is used to conduct volumetric DDoS attacks targeting CDNs, game servers and enterprises while deliberately avoiding sensitive IP ranges to increase survivability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.