Masjesu, a commercial DDoS-for-hire botnet active since early 2023, compromises IoT devices and is marketed primarily through Telegram. It targets exposed devices through known vulnerabilities affecting GPON equipment and Netgear products, then maintains access using cron-based persistence, process hiding, and XOR obfuscation to evade detection.
The botnet supports UDP, TCP, SYN, ACK, GRE, RDP, and HTTP flood attacks. Its operators claimed an ACK-flood attack of roughly 290 Gbit/s in October 2025, demonstrating substantial disruptive capacity. Defenders should investigate connections to identified command-and-control infrastructure, including 158.94.208.122, 178.16.54.252, and associated domains, while patching vulnerable IoT devices and restricting their internet exposure.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Masjesu operators posted a claim of an ACK-flood DDoS attack reaching approximately 290 Gbit/s. Traffic associated with the claimed attack was primarily observed from Vietnam, with additional sources in Ukraine, Iran, Brazil, Kenya, and India.
After the original Masjesu Telegram channel was removed for platform-rule violations, operators created a new channel, “Masjesu Botnet / 僵尸网络.” The original @synmaestro account was replaced with @synmaestr0.
The commercial Masjesu IoT botnet began operating as a DDoS-for-hire service, targeting routers, gateways, and other embedded devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.