Masjesu Botnet Launches DDoS Attacks Targeting IoT Devices

Masjesu Botnet Launches DDoS Attacks Targeting IoT Devices

First seen 8 Apr 2026, 20:17 UTC GbhackersThehackernewsGround.NewsSecurityaffairs.CoScworld 66.5

Article Content

Browse articles
ThreatCluster

The Masjesu botnet, also known as XorBot, has been identified as a DDoS-for-hire service targeting routers and IoT devices since 2023. It operates stealthily, avoiding high-profile networks to evade detection while executing high-volume distributed denial-of-service attacks. The botnet has been advertised on Telegram and is capable of exploiting various architectures, turning everyday network hardware into tools for commercial attacks. As of 2026, Masjesu remains active and continues to reshape the DDoS landscape, posing significant risks to organizations relying on exposed IoT infrastructure. The botnet's maturity and stealth tactics highlight the evolving threat posed by such malicious services in the cybersecurity domain.

Key Points: • Masjesu botnet has been operational since 2023, targeting IoT devices. • It utilizes stealth tactics to avoid detection while executing DDoS attacks. • The botnet is advertised as a DDoS-for-hire service on Telegram.

Timeline

2023-01-01
Masjesu botnet first surfaced as a DDoS-for-hire service.
2025-07-01
Masjesu botnet reaches multiterabit attack capacity.
2026-04-08
Recent reports confirm Masjesu's ongoing DDoS activities.