Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world

Hackers steal and leak confidential Los Angeles Police Department documents

OpenAI releases new safety blueprint to combat rising child sexual exploitation

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world
Identity

Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world

By April 8, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 8, 2026IoT security/network security

Masjes Botnet

Cybersecurity researchers have lifted the curtain on a stealth botnet designed for distributed denial of service (DDoS) attacks.

The botnet, called Masjesu, has been promoted as a rental DDoS service through Telegram since it first appeared in 2023. This botnet can target a wide range of IoT devices across multiple architectures, including routers and gateways.

“Created with persistence and low visibility in mind, Masjes deliberately avoids blocklisted IP ranges, such as those belonging to the Department of Defense (DoD), to ensure long-term survival, preferring a cautious and conservative approach to widespread infection,” Trellix security researcher Mohideen Abdul Kader F. said in a report on Tuesday.

It is worth noting that this commercial product also goes by the name XorBot, as it uses XOR-based encryption to hide strings, configurations, and payload data. This information was first documented by Chinese security vendor NSFOCUS in December 2023 and was associated with an operator named “synmaestro.”

A subsequent iteration of the botnet observed a year later was found to have added and gained initial access to 12 different command injection and code execution exploits targeting routers, cameras, DVRs, and NVRs from D-Link, Eir, GPON, Huawei, Intelbras, MVPower, NETGEAR, TP-Link, and Vacron. A new module has also been added to perform DDoS flood attacks.

“As an emerging botnet family, XorBot has shown strong growth momentum, continually infiltrating and taking control of new IoT devices,” NSFOCUS said in November 2024. “In particular, these controllers are increasingly using social media platforms such as Telegram as their primary channel for recruitment and promotion, attracting target ‘customers’ through initial aggressive promotional efforts and laying a solid foundation for subsequent botnet expansion and development.”

Trellix’s latest findings show that Masjesu touted its diverse botnet infrastructure and suitability for targeting content delivery networks (CDNs), game servers, and enterprises, touting its ability to carry out high-volume DDoS attacks. Attacks by this botnet primarily originate from Vietnam, Ukraine, Iran, Brazil, Kenya, and India, with Vietnam accounting for nearly 50% of observed traffic.

Once deployed on a compromised device, the malware creates a socket and binds to a hardcoded TCP port (55988), allowing the attacker to connect directly. If this operation fails, the attack chain is stopped immediately.

Otherwise, the malware could initiate persistence settings, ignore termination-related signals, and kill commonly used processes such as wget and curl to thwart competing botnets. It then connects to an external server to receive DDoS attack commands and execute them against the intended target.

Masjesu also has self-propagation capabilities, allowing it to probe random IP addresses for open ports and integrate successfully compromised devices into the infrastructure. One notable addition to the list of exploit targets is Realtek routers. This is done by scanning port 52869 associated with the Realtek SDK’s sminiigd daemon. Several DDoS botnets, including JenX and Satori, have adopted the same approach in the past.

“Botnets continue to grow by infecting a wide range of IoT devices across multiple architectures and manufacturers,” Trellix said. “In particular, Masges appears to avoid targeting sensitive and important organizations that could arouse significant legal or law enforcement attention, a strategy that is likely to improve the long-term viability of the organization.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHackers steal and leak confidential Los Angeles Police Department documents

Related Posts

APT28 deploys PRISMEX malware in campaign targeting Ukraine and NATO allies

April 8, 2026

Reduce your IAM attack surface through the Identity Visibility and Intelligence Platform (IVIP)

April 8, 2026

Anthropic’s Claude Mythos discovers thousands of zero-day flaws across major systems

April 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world

Hackers steal and leak confidential Los Angeles Police Department documents

OpenAI releases new safety blueprint to combat rising child sexual exploitation

The developer of VeraCrypt encryption software said Windows users may face startup issues after Microsoft locks their accounts.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.