HomeSecurityMasjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

Cybersecurity researchers have uncovered a botnet designed for distributed denial-of-service (DDoS) . The Masjesu botnet has been advertised on Telegram as a DDoS-for-hire. It is capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures.

Masjesu Botnet DDoS

“ Designed for persistence and low visibility, Masjesu prefers careful, low-key execution over widespread infection, intentionally avoiding blocked IP ranges, such as those owned by the Department of Defense (DoD) , ” Trellix security researcher Mohideen Abdul Khader F said in a report.

Masjesu botnet or XorBot

It is worth noting that the commercial offering is also known as XorBot due to its use of XOR-based encryption to hide strings, configurations, and payload data. It was first recorded by Chinese security vendor NSFOCUS in December 2023. At the time, it was associated with an operator called “synmaestro.”

See also: Mac: New ClickFix attack abuses Script Editor

A subsequent version of the botnet, observed a year later, was found to have added 12 different command injection and code execution exploits to target routers, cameras, DVRs and NVRs from D-Link, Eir, GPON, Huawei, Intelbras, MVPower, NETGEAR, TP-Link and Vacron. This was how the malware gained initial access.

New models for executing DDoS flood attacks.

“As an emerging botnet family, XorBot shows a strong growth momentum, continuously infiltrating and controlling new IoT devices,” NSFOCUS reported. “These controllers are increasingly willing to use social media platforms, such as Telegram, as primary channels for recruitment and promotion, attracting target ‘customers’ through initial active promotional activities, laying a solid foundation for the botnet’s subsequent expansion and growth.”

The latest findings from Trellix show that the Masjesu botnet has evolved the ability to carry out volumetric DDoS attacks, highlighting its diverse infrastructure and its suitability for targeting content delivery networks (CDNs), game servers, and enterprises.

See also: FBI Disrupts APT28's DNS Hijacking Network

The attacks carried out by the botnet mainly originate from Vietnam, Ukraine, Iran, Brazil, Kenya and India, with Vietnam representing almost 50% of the observed traffic.

Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

How does a botnet work?

Once deployed to a compromised device, the malware creates and binds a socket with a hard-coded TCP port (55988), to allow the attacker to connect directly. If this operation fails, the attack chain is immediately aborted. Otherwise, the malware proceeds to set persistence, ignores abort-related signals, stops commonly used processes such as wget and curl (possibly to disrupt competing botnets), and then connects to an external server to receive DDoS attack commands to execute against targets of interest.

The Masjesu botnet also has self-replicating capabilities , which allows it to scan random IP addresses for open ports and successfully integrate compromised devices into its infrastructure. A notable addition to the list of exploit targets are Realtek routers.

According to the researchers, Masjesu appears to avoid targeting sensitive critical organizations that could trigger significant legal proceedings or law enforcement involvement.

See also: Zero-click Grafana AI attack allows data extraction

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

Protection

To protect against botnets like Masjesu, it is important to promptly change the default credentials on all IoT devices (routers, cameras, etc.), apply regular firmware updates, and disable unnecessary services and open ports. In addition, using a strong firewall, isolating IoT devices on a separate network (network segmentation), and monitoring outbound traffic for suspicious patterns can prevent participation in DDoS attacks. Finally, disabling remote access, where not needed, significantly reduces the attack surface.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS