Skip to content
Masjesu Botnet Launches DDoS Attacks Targeting IoT Devices

Masjesu Botnet Launches DDoS Attacks Targeting IoT Devices

First seen 8 Apr 2026, 20:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 9, 2026 at 19:59 UTC
  • •Masjesu botnet has been operational since 2023, targeting IoT devices.
  • •It utilizes stealth tactics to avoid detection while executing DDoS attacks.
  • •The botnet is advertised as a DDoS-for-hire service on Telegram.

The Masjesu botnet, also known as XorBot, has been identified as a DDoS-for-hire service targeting routers and IoT devices since 2023. It operates stealthily, avoiding high-profile networks to evade detection while executing high-volume distributed denial-of-service attacks. The botnet has been advertised on Telegram and is capable of exploiting various architectures, turning everyday network hardware into tools for commercial attacks. As of 2026, Masjesu remains active and continues to reshape the DDoS landscape, posing significant risks to organizations relying on exposed IoT infrastructure. The botnet's maturity and stealth tactics highlight the evolving threat posed by such malicious services in the cybersecurity domain.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

Timeline

2023-01-01
Masjesu botnet first surfaced as a DDoS-for-hire service.
2025-07-01
Masjesu botnet reaches multiterabit attack capacity.
2026-04-08
Recent reports confirm Masjesu's ongoing DDoS activities.

More articles in this cluster (5)

Following this threat?

Track Masjesu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed