Nexus Zeta is the online alias associated with Kenneth Currin Schuchman, a U.S.-based actor linked to the Mirai-derived botnets Satori, Masuta, and PureMasuta. The actor is known for developing and operating malware targeting Internet of Things devices, especially routers, and for using those botnets in disruptive distributed denial-of-service activity. Satori, also referred to as Masuta and also identified in some reporting as Mirai Okiru, rapidly infected large numbers of IoT devices in 2017 and was observed exploiting vulnerabilities in Huawei routers. Subsequent activity tied the same actor to Masuta and PureMasuta, including use of a D-Link HNAP-related exploit chain to expand botnet infections. Nexus Zeta has been characterized as an initially inexperienced but fast-developing Mirai-variant operator whose operational security failures enabled attribution. The actor sought attention for botnet activity, contacted researchers and journalists about the growth of the malware, and was linked through chats, social-media activity, infrastructure overlap, and leaked source code analysis. Research connecting Satori, Masuta, and PureMasuta indicates continued malware development and reuse of shared command-and-control infrastructure. The actor’s observed capabilities center on initial access through exploitation of vulnerable IoT devices, large-scale scanning for additional victims, botnet propagation, and DDoS operations. Reported exploitation included SOAP- and TR-069-related weaknesses and Huawei- and D-Link-device vulnerabilities to achieve arbitrary code execution and expand infections. Available information supports classification as a financially motivated cybercriminal actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor has already been observed in implementing two other known SOAP related exploits, CVE-2014–8361 and CVE-2017–17215 in his Satori botnet project.
The threat actor has already been observed in implementing two other known SOAP related exploits, CVE-2014–8361 and CVE-2017–17215 in his Satori botnet project.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged operator/author of the Satori (Masuta) IoT botnet, which infected hundreds of thousands of routers and IoT devices and was used for large-scale DDoS activity.
Linked to the Mirai variants Satori/Okiru, Masuta, and PureMasuta, and associated with attacks against Huawei routers and growth of IoT botnets using SOAP-related exploits.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.