Masjesu, also known as XorBot, is a Mirai-derived IoT botnet active since 2023 and marketed as a DDoS-for-hire service, principally through Telegram. It compromises routers, gateways, cameras, DVRs, NVRs, and other embedded devices across numerous processor architectures. Propagation combines random-address scanning with exploitation of known command-injection and remote-code-execution vulnerabilities, including CVE-2018-10561, CVE-2018-10562, and CVE-2024-12847, affecting devices from vendors such as D-Link, Huawei, Netgear, TP-Link, Realtek, MVPower, Vacron, and Eir.
The malware emphasizes persistence and stealth. It uses layered XOR obfuscation and runtime decryption, daemonizes itself, disguises its process identity as a system component, ignores termination signals, establishes recurring scheduled-task persistence, and attempts to terminate competing malware and administrative utilities. It avoids selected sensitive and private address ranges while scanning for further vulnerable devices.
Compromised systems receive command-and-control instructions over web-based communications and can conduct volumetric DDoS attacks, including UDP, TCP, SYN, ACK, GRE, VSE, RDP, OSPF, ICMP, IGMP, and HTTP floods. The operators have promoted the botnet for attacks against content-delivery networks, game servers, and enterprises, and reported attack activity has reached approximately 290 Gbps. Public reporting has associated the operation with the handle synmaestro.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Le botnet Masjesu propage ses infections par scan d’IP aléatoires et exploitation de vulnérabilités, notamment sur les équipements GPON : CVE-2018-10561 et CVE-2018-10562. | Masjesu est un botnet IoT à vocation commerciale, proposé en tant que service DDoS-for-hire principalement via Telegram. Il exploite notamment CVE-2018-10561, CVE-2018-10562 et CVE-2024-12847 pour sa propagation.
La fonction de propagation « Createchildrenreplic » de Masjesu scanne des adresses IP aléatoires et exploite des vulnérabilités sur plusieurs équipements, dont Netgear (CVE-2024-12847). | Masjesu est un botnet IoT à vocation commerciale, proposé en tant que service DDoS-for-hire principalement via Telegram. Il exploite notamment CVE-2018-10561, CVE-2018-10562 et CVE-2024-12847 pour sa propagation.
Le botnet Masjesu propage ses infections par scan d’IP aléatoires et exploitation de vulnérabilités, notamment sur les équipements GPON : CVE-2018-10561 et CVE-2018-10562. | Masjesu est un botnet IoT à vocation commerciale, proposé en tant que service DDoS-for-hire principalement via Telegram. Il exploite notamment CVE-2018-10561, CVE-2018-10562 et CVE-2024-12847 pour sa propagation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Called Masjesu, the botnet has been advertised via Telegram as a DDoS-for-hire service since it first surfaced in 2023. It's capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
« Domaines anciens : conn.masjesu.zip, Gpbtpz.rodeo » ; « Domaines récents : conn.elbbird.zip … conn.f12screenshot.xyz »
MITRE ATT&CK ID Technique Evidence T1583.003 Acquire Infrastructure: Virtual Private Server Bulgarian VPS (AS213438) for C2 and stealer hosting
« Chiffrement XOR multi-étapes (clés 0x16, 0x9F, 0x8) pour protéger les chaînes critiques (domaines C2, chemins, noms de processus) »
To achieve persistence, the malware renames itself as a legitimate system file (e.g., /usr/lib/ld-unix.so.2)... It also spoofs process names like systemd-journald to avoid detection.
...then connects to an external server to receive DDoS attack commands for executing them against targets of interest.
« Téléchargement d’un script shell depuis le C2 via HTTP GET /.shell »
« Méthodes DDoS supportées : UDP Flood, TCP Flood, VSE Flood, GRE Flood, RDP Flood, OSPF Flood, ICMP Flood, IGMP Flood, ProtoRand, TCP SYN, TCP ACK, TCP ACKPSH, HTTP Flood »
MITRE ATT&CK ID Technique Evidence T1498.001 Network Denial of Service: Direct Network Flood UDP, TCP, ICMP, GRE, OSPF floods
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet IoT commercial fournissant des attaques DDoS à la demande. Il cible des routeurs, passerelles et équipements embarqués multi-architectures, se propage par analyse d'adresses IP et exploitation de vulnérabilités publiques, établit une persistance via cron et dissimule son exécutable/processus sous des noms système légitimes. Il prend en charge de nombreux floods réseau et applicatifs, dont UDP, TCP, SYN, ACK, HTTP, GRE, ICMP et RDP.
Mirai-derived IoT DDoS botnet that self-propagates across vulnerable consumer and SOHO networking devices, deploys payloads for 17 CPU architectures, uses XOR-encrypted C2 communications, performs honeypot detection, and launches volumetric floods across multiple protocols including UDP, TCP, VSE, GRE, RDP, OSPF, and ICMP.
IoT-focused botnet used as a DDoS-for-hire service. It targets routers and gateways across multiple architectures, uses XOR encryption, emphasizes stealth and persistence, exploits command injection and code execution flaws for initial access, and propagates by scanning for vulnerable devices.
A stealthy IoT botnet marketed via Telegram as a DDoS-for-hire service. It targets routers, gateways, and embedded devices across multiple CPU architectures, uses XOR encryption to hide strings/configs/payloads, persists via cron jobs and process masquerading, scans random IPs for vulnerable devices, exploits known flaws in products such as D-Link, GPON, and Netgear, and executes TCP, UDP, and HTTP flood attacks under C2 control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.