Cybersecurity researchers have uncovered a botnet designed for distributed denial-of-service (DDoS) . The Masjesu botnet has been advertised on Telegram as a DDoS-for-hire. It is capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures.

“ Designed for persistence and low visibility, Masjesu prefers careful, low-key execution over widespread infection, intentionally avoiding blocked IP ranges, such as those owned by the Department of Defense (DoD) , ” Trellix security researcher Mohideen Abdul Khader F said in a report.
Masjesu botnet or XorBot
It is worth noting that the commercial offering is also known as XorBot due to its use of XOR-based encryption to hide strings, configurations, and payload data. It was first recorded by Chinese security vendor NSFOCUS in December 2023. At the time, it was associated with an operator called “synmaestro.”
See also: Mac: New ClickFix attack abuses Script Editor
A subsequent version of the botnet, observed a year later, was found to have added 12 different command injection and code execution exploits to target routers, cameras, DVRs and NVRs from D-Link, Eir, GPON, Huawei, Intelbras, MVPower, NETGEAR, TP-Link and Vacron. This was how the malware gained initial access.
New models for executing DDoS flood attacks.
“As an emerging botnet family, XorBot shows a strong growth momentum, continuously infiltrating and controlling new IoT devices,” NSFOCUS reported. “These controllers are increasingly willing to use social media platforms, such as Telegram, as primary channels for recruitment and promotion, attracting target ‘customers’ through initial active promotional activities, laying a solid foundation for the botnet’s subsequent expansion and growth.”
The latest findings from Trellix show that the Masjesu botnet has evolved the ability to carry out volumetric DDoS attacks, highlighting its diverse infrastructure and its suitability for targeting content delivery networks (CDNs), game servers, and enterprises.
See also: FBI Disrupts APT28's DNS Hijacking Network
The attacks carried out by the botnet mainly originate from Vietnam, Ukraine, Iran, Brazil, Kenya and India, with Vietnam representing almost 50% of the observed traffic.

How does a botnet work?
Once deployed to a compromised device, the malware creates and binds a socket with a hard-coded TCP port (55988), to allow the attacker to connect directly. If this operation fails, the attack chain is immediately aborted. Otherwise, the malware proceeds to set persistence, ignores abort-related signals, stops commonly used processes such as wget and curl (possibly to disrupt competing botnets), and then connects to an external server to receive DDoS attack commands to execute against targets of interest.
The Masjesu botnet also has self-replicating capabilities , which allows it to scan random IP addresses for open ports and successfully integrate compromised devices into its infrastructure. A notable addition to the list of exploit targets are Realtek routers.
According to the researchers, Masjesu appears to avoid targeting sensitive critical organizations that could trigger significant legal proceedings or law enforcement involvement.
See also: Zero-click Grafana AI attack allows data extraction
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection
To protect against botnets like Masjesu, it is important to promptly change the default credentials on all IoT devices (routers, cameras, etc.), apply regular firmware updates, and disable unnecessary services and open ports. In addition, using a strong firewall, isolating IoT devices on a separate network (network segmentation), and monitoring outbound traffic for suspicious patterns can prevent participation in DDoS attacks. Finally, disabling remote access, where not needed, significantly reduces the attack surface.
