Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
TP-Link Systems Inc.

TP-Link Systems Inc. Vendor Cyber Rating & Cyber Score

tp-link.com

Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world's top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people's lives through faster, more reliable connectivity. With a commitment to excellence, TP-Link serves customers in over 170 countries and continues to grow its global footprint. For career-related inquiries, please contact [email protected].


TSI A.I CyberSecurity Scoring

TSI
Company Information
Website:https://www.tp-link.com/us/
Employees number:382
Number of followers:31,892
NAICS:334
Industry Type:Computers and Electronics Manufacturing
Homepage:tp-link.com
TSI Risk Score (AI oriented)
Between 600 and 649
logo
TSIComputers and Electronics Manufacturing
Updated:
03/08/2026
646/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
TSI Global Score (TPRM)
xxxx
logo
TSIComputers and Electronics Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TSI
TSIPoor
Current Score
646Caa (POOR)
01000
10 incidents
-6.71 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
646Before Incident
JULY 2026
642Before Incident
JUNE 2026
639Before Incident
MAY 2026
644Before Incident
Vulnerability
28 May 2026TSI
TP-Link: TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks

TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router

639After Incident
CRITICAL-5
TP-1785774351
TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router TP-Link has released a security advisory addressing a high-severity vulnerability (CVE-2026-12935) in its TL-WR940N V6 wireless router. The flaw, rated 8.7 on the CVSS v4.0 scale, could allow unauthenticated attackers to trigger a denial-of-service (DoS) condition or execute remote code under specific conditions. The vulnerability stems from a stack-based buffer overflow in the router’s RTSP (Real-Time Streaming Protocol) connection tracking module, which processes network traffic within the device’s kernel. Exploitation requires a local network client to connect to a malicious RTSP server, which then sends crafted data to corrupt memory in the router. Successful attacks could crash the device or enable arbitrary code execution, granting attackers control over network settings, traffic interception, DNS manipulation, or further compromise of connected devices. The flaw affects only the TL-WR940N V6 hardware version, with regional firmware updates now available: - English models: (EN)_V6_260528 - US models: (US)_V6_260528 - Japanese models: (JP)_V6_260527 Users are advised to verify their router’s hardware version and regional firmware before applying updates, as incorrect installations may cause malfunctions. TP-Link credited Ryo Shimada of Powder Keg Technologies for the responsible disclosure. Until patches are applied, mitigations include restricting outbound RTSP connections and monitoring for suspicious activity, such as unexpected reboots or configuration changes.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: TL-WR940N V6 wireless routerDowntime: Denial-of-Service (DoS) conditionOperational Impact: Device crash, arbitrary code execution, control over network settings, traffic interception, DNS manipulation, further compromise of connected devices
MAY 2026
648Before Incident
Vulnerability
20 May 2026TSI
TP-Link: Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras

643After Incident
CRITICAL-5
TP-1784276626
TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras, which could allow attackers on the same local network to access sensitive data. The most critical flaw, CVE-2026-9770 (CVSS 8.6), involves a hardcoded cryptographic key embedded in the camera’s firmware. Exploitation could enable man-in-the-middle (MitM) attacks, allowing threat actors to intercept communications, steal administrative credentials, or manipulate traffic. Attackers could leverage this on shared Wi-Fi networks, compromised routers, or poorly segmented office networks. The second vulnerability, CVE-2026-13230 (CVSS 5.3), affects the cameras’ local discovery mechanism, exposing geolocation-related data without authentication. While this flaw only impacts confidentiality, it could still aid attackers in reconnaissance. Both issues have been patched in firmware versions 2.4.0 Build 20260520 and 2.4.1 Build 20260621. TP-Link advises users to update via the Kasa app or official support portal and recommends network segmentation to mitigate risks until patches are applied. Unpatched devices remain vulnerable to exploitation.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data, administrative credentials, geolocation-related dataSystems Affected: Kasa EC70 v4 and EC71 v4 smart cameras
DATA BREACH
Type Of Data Compromised: Administrative credentials, geolocation-related dataSensitivity Of Data: High (credentials), Medium (geolocation)
APRIL 2026
650Before Incident
Vulnerability
20 Apr 2026TSI
TP-Link: Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware

Nexcorium Botnet Exploits Unpatched TBK DVRs and TP-Link Routers in Large-Scale DDoS Campaign

645After Incident
CRITICAL-5
TP-1776673453
Nexcorium Botnet Exploits Unpatched TBK DVRs and TP-Link Routers in Large-Scale DDoS Campaign A newly uncovered botnet campaign is exploiting a critical vulnerability in TBK digital video recorders (DVRs) to deploy Nexcorium, a Mirai-based malware designed for large-scale distributed denial-of-service (DDoS) attacks. The flaw, CVE-2024-3721 (CVSS 6.3), affects TBK’s DVR-4104 and DVR-4216 models, which remain widely deployed in small businesses, retail outlets, and surveillance systems due to outdated firmware and weak default credentials. Attackers exploit the vulnerability by sending a crafted HTTP request to the endpoint `/device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___`, enabling unauthenticated remote code execution (RCE). Once compromised, the device is enslaved into the botnet, with Nexcorium displaying the message “nexuscorp has taken control” upon execution a deliberate signature left by the threat actors. Researchers at Fortinet’s FortiGuard Labs analyzed the campaign, confirming Nexcorium’s Mirai lineage, including an XOR-encoded configuration table, a watchdog module for persistence, and a DDoS attack module capable of flooding targets on command. The malware also targets end-of-life TP-Link Wi-Fi routers via CVE-2017-17215, expanding its reach by exploiting unpatched legacy hardware. Nexcorium employs multiple persistence mechanisms, including self-replicating binaries, C2 (command-and-control) communication channels, and Telnet brute-force attacks to propagate across networks. It supports multiple CPU architectures, allowing it to infect a broader range of IoT devices. A watchdog process ensures the malware restarts if terminated, while FNV-1a hashing verifies binary integrity, restoring itself if altered. The botnet’s dual-target strategy leveraging both TBK DVRs and TP-Link routers creates a geographically distributed attack infrastructure capable of generating massive, hard-to-block DDoS traffic. Since compromised devices operate behind real IP addresses, their traffic appears legitimate, complicating mitigation efforts. With no patch available for CVE-2024-3721, security researchers recommend replacing affected TBK DVRs and vulnerable TP-Link routers. Network segmentation and disabling unnecessary remote access to DVR management interfaces are also advised to limit exposure.
INCIDENT DETAILS -
TYPE
Botnet / DDoS Campaign
MOTIVATION
Large-scale DDoS attacks
IMPACT
Systems Affected: TBK DVRs (DVR-4104, DVR-4216) and TP-Link Wi-Fi routersOperational Impact: Compromised devices enslaved into botnet for DDoS attacks
APRIL 2026
654Before Incident
Vulnerability
16 Apr 2026TSI
TP-Link: TP-Link Router Vulnerability Enables Arbitrary Command Execution

High-Severity Command Injection Flaw Disclosed in TP-Link Routers

650After Incident
CRITICAL-4
TP-1780381426
High-Severity Command Injection Flaw Disclosed in TP-Link Routers A critical authenticated command injection vulnerability, tracked as CVE-2026-5509 (CVSS v4.0: 8.5), has been identified in two TP-Link router models the Archer BE450 v1 and Archer BE7200 v1. The flaw allows attackers to execute arbitrary OS commands via the web management interface after gaining admin access, due to insufficient input sanitization in the backend. Exploitation requires network adjacency and high privileges but involves low complexity and no user interaction. Successful attacks could grant full device control, enabling threat actors to intercept network traffic, modify system configurations, or deploy unauthorized services posing significant risks to data privacy. The vulnerability mirrors past TP-Link router flaws, including CVE-2025-14756 (Archer MR600) and CVE-2023-1389 (Archer AX21), highlighting a recurring pattern of command injection risks in the Archer product line. Affected Models & Remediation The flaw impacts Archer BE450 v1 and BE7200 v1 running firmware versions earlier than 1.3.0 Build 20260416. TP-Link has released a patch, and users are advised to upgrade immediately. Notably, these models are not sold in the U.S., with distribution primarily in markets like Japan. While patching is the primary mitigation, administrators should also enforce strong credentials, restrict web management access, and disable remote management unless necessary. Given TP-Link’s history of similar vulnerabilities, regular firmware audits are recommended for ongoing security.
INCIDENT DETAILS -
TYPE
Command Injection
IMPACT
Data Compromised: Network traffic interception, system configurations, unauthorized services deploymentSystems Affected: Archer BE450 v1, Archer BE7200 v1Operational Impact: Full device control, potential data privacy risks
DATA BREACH
Type Of Data Compromised: Network traffic, system configurationsSensitivity Of Data: High (potential data privacy risks)
APRIL 2026
658Before Incident
Vulnerability
07 Apr 2026TSI
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials

Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign

654After Incident
CRITICAL-4
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations. ### How the Attack Works APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value. In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services. Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks. ### Impact and Attribution The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear. This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
Cyberespionage
MOTIVATION
Cyberespionage, credential theft for intelligence gathering
IMPACT
Data Compromised: Passwords, OAuth tokens, credentials from web and email servicesSystems Affected: TP-Link WR841N routers, downstream devices (laptops, phones)Identity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials (passwords, OAuth tokens), web and email service dataSensitivity Of Data: High (personally identifiable information, authentication tokens)Data Exfiltration: YesPersonally Identifiable Information: Yes
MARCH 2026
663Before Incident
Vulnerability
28 Mar 2026TSI
Microsoft, Splunk, Fortinet, TP-Link, Dell and AWS: Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories

Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits Dominate July 2026

658After Incident
CRITICAL-5
DELMICAMAFORSPLTP-1784478360
Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits Dominate July 2026 This week’s cybersecurity landscape underscored the relentless expansion of attack surfaces, with high-impact vulnerabilities, active exploits, and emerging threats targeting everything from enterprise identity systems to AI-driven workflows. Microsoft’s Patch Tuesday Highlights Critical Exploits Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including two actively exploited zero-days: - CVE-2026-56164 (SharePoint Server): Allows remote code execution (RCE) via crafted requests. - CVE-2026-56155 (Active Directory Federation Services): Enables privilege escalation, posing risks to enterprise identity infrastructure. A BitLocker bypass bug (publicly disclosed) and a Windows User Profile Service exploit (LegacyHive PoC) further exposed post-patch risks, allowing standard users to hijack registry hives. WordPress Under Siege: 500M Sites at Risk A pre-authentication RCE flaw (wp2shell, CVE-2026-60137/CVE-2026-63030) in WordPress’s REST API batch-route functionality threatens over 500 million sites, enabling unauthenticated takeovers via SQL injection. The vulnerability remains unpatched for many deployments. Big Four Breach: EY Confirms Client Data Exposure Ernst & Young disclosed a breach between March 28 and April 12, 2026, where an unauthorized third party accessed its IT support ticket platform, exfiltrating client tax and investment documents. Detection lagged nearly three weeks, raising concerns about incident response in professional services firms. AI Systems Emerge as New Attack Vectors Adversaries are increasingly targeting AI integrations: - Claude for Chrome: A flaw in the browser extension exposed users to potential data theft. - GhostCommit: A novel technique hides malicious AI prompts within code commits, manipulating coding assistants undetected. - GPT-5/6 Exploit Chain: Researchers demonstrated an attack pairing AI models ("Sol") with Chrome vulnerabilities, signaling a shift toward AI-assisted cyberattacks. Malicious Extensions and Supply Chain Risks - ModHeader: A popular Chrome/Edge extension (1.6M installs) was removed after dormant code was found exfiltrating browsing history to an external server. - 7-Zip: A critical flaw enables code execution via crafted archives, impacting widespread file-handling workflows. - Notepad++ v8.9.7: Patched multiple high-risk bugs, including PowerShell command injection and Zip Slip path traversal. Enterprise and Cloud Threats Persist - Dell: Two separate issues emerged BIOS firmware flaws exposing admin passwords and a July 2026 update causing unexpected laptop shutdowns. - Fortinet/F5/Splunk: Vendors released patches for 10+ vulnerabilities, including Nginx-related flaws (F5) and data-integrity risks (Splunk). - AWS Cost Explorer: A bug introduced security and data-exposure risks for cloud billing monitoring. - TP-Link Cameras: A flaw could allow attackers to compromise device functionality or access video feeds. The week’s disclosures reflect a broadening threat landscape, where legacy systems, AI tools, and third-party integrations remain prime targets for exploitation.
INCIDENT DETAILS -
TYPE
Zero-day exploitData breachRCEPrivilege escalationAI-assisted attackSupply chain attack
IMPACT
Client tax and investment documentsBrowsing historyAdmin passwordsVideo feedsSharePoint ServerActive Directory Federation ServicesWordPress sitesEY IT support ticket platformClaude for ChromeChrome/Edge (ModHeader extension)7-ZipNotepad++Dell laptopsFortinet/F5/Splunk systemsAWS Cost ExplorerTP-Link camerasUnexpected laptop shutdownsDevice functionality compromise
DATA BREACH
Client tax and investment documentsBrowsing historyAdmin passwordsSensitivity Of Data: High
FEBRUARY 2026
678Before Incident
Cyber Attack
01 Feb 2026TSI
Ruijie, TP-Link and Hadoop: RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

RustDuck: A Stealthy, Rust-Based Botnet Targeting Routers and Servers

659After Incident
HIGH-19
RUITP-HOR1782865482
RustDuck: A Stealthy, Rust-Based Botnet Targeting Routers and Servers Researchers at QiAnXin’s XLab have uncovered RustDuck, a two-stage malware family actively hijacking home routers, IP cameras, Android devices, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. First tracked in February 2026, RustDuck stands out not for its current scale but for its rapid evolution and sophisticated evasion tactics. ### Infection Vectors RustDuck spreads through multiple well-known vulnerabilities, exploiting: - Default or weak credentials on Telnet and SSH services. - Unpatched flaws in devices from TVT (DVRs/cameras), Ruijie, TP-Link, ZTE, and Android debugging interfaces. - Vulnerable web software, including ThinkPHP, Jenkins, and Hadoop YARN. Over 20 IP addresses have been identified as distribution points, with the most active 176.65.139[.]204 sharing address space with a separate ADB-targeting botnet reported earlier in 2026. ### Evasion and Stealth RustDuck’s design prioritizes evasion, employing a two-stage infection process: 1. A lightweight loader decrypts and deploys a core module, increasingly rewritten in Rust a language that complicates reverse engineering compared to traditional C-based malware. 2. The core module performs extensive anti-analysis checks, including: - Detecting debuggers (e.g., Wireshark, gdb), virtual machines, and honeypots. - Testing for reserved IP responses to identify fake networks. - Comparing system clocks to detect sandbox time acceleration. Communication is encrypted using ChaCha20-Poly1305 and AES-GCM, with keys rotated every 10 minutes. Traffic mimics legitimate HTTPS to avoid detection. Command-and-control (C2) servers leverage dynamic DNS services like duckdns.org, allowing operators to issue DDoS commands, update malware, or switch C2 addresses. ### Broader Context RustDuck follows a growing trend of Rust-based botnets, such as RustoBot (documented in April 2025), which targeted routers for DDoS attacks. While smaller than record-breaking botnets like AISURU (3M+ devices, 30 Tbps attacks), RustDuck’s advanced techniques Rust rewrites and anti-analysis measures signal a shift toward more resilient malware. The botnet’s infrastructure overlaps with other DDoS operations, suggesting possible shared hosting or coordinated activity. Though currently limited in scale, its development pace and evasion methods could inspire future threats.
INCIDENT DETAILS -
TYPE
Botnet, DDoS
MOTIVATION
DDoS attacks, botnet expansion
IMPACT
Systems Affected: Home routers, IP cameras, Android devices, poorly secured serversOperational Impact: Potential DDoS attacks on targeted systems
JANUARY 2026
678Before Incident
DECEMBER 2025
675Before Incident
NOVEMBER 2025
675Before Incident
OCTOBER 2025
673Before Incident
SEPTEMBER 2025
671Before Incident
AUGUST 2025
687Before Incident
Cyber Attack
01 Aug 2025TSI
TP-Link: US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure

U.S. Disrupts Russian GRU’s Global Router Hijacking Campaign Targeting Governments and Critical Infrastructure

667After Incident
CRITICAL-20
TP-1775665616
U.S. Disrupts Russian GRU’s Global Router Hijacking Campaign Targeting Governments and Critical Infrastructure The U.S. Department of Justice (DOJ) announced on Tuesday that it had dismantled a years-long cyberespionage operation by Russia’s military intelligence agency, the GRU, which had hijacked thousands of small office and home office (SOHO) routers worldwide to intercept sensitive data. The campaign, active since at least 2024 (with evidence dating back to August 2025), exploited TP-Link routers to reroute DNS requests through Kremlin-controlled servers, enabling the theft of emails, passwords, and other confidential information from governments, critical infrastructure operators, and private networks. The FBI’s "Operation Masquerade" neutralized the threat by remotely resetting compromised routers and collecting forensic evidence, effectively severing Russia’s access. The operation followed a Microsoft report revealing that the GRU’s hacking group tracked as APT28, Fancy Bear, or Forest Blizzard had weaponized DNS hijacking to conduct adversary-in-the-middle (AiTM) attacks, particularly targeting Microsoft Outlook connections. An automated filtering system allowed the hackers to prioritize high-value targets, including three African government organizations, as well as entities in IT, telecommunications, and energy sectors. Microsoft warned that the scale of compromised routers could amplify future AiTM attacks, though no malware delivery or denial-of-service activity has been observed yet. The GRU’s tactics reflect an evolution in its playbook, marking the first time the group has used DNS hijacking at scale to exploit edge devices for large-scale surveillance. The disruption aligns with the FBI’s broader strategy to proactively counter state-sponsored cyber threats. Brett Leatherman, head of the FBI’s Cyber Division, emphasized the agency’s commitment to imposing costs on foreign adversaries targeting U.S. interests. The UK’s National Cyber Security Centre (NCSC) also issued an advisory on the campaign, underscoring the risks of unpatched or end-of-life networking equipment.
INCIDENT DETAILS -
TYPE
Cyberespionage, DNS Hijacking, Adversary-in-the-Middle (AiTM) Attack
MOTIVATION
Cyberespionage, surveillance, data theft
IMPACT
Data Compromised: Emails, passwords, confidential informationSystems Affected: Thousands of SOHO routers (TP-Link), government and critical infrastructure networksOperational Impact: Data interception, surveillance, potential future amplification of AiTM attacksIdentity Theft Risk: High (PII exposure)
DATA BREACH
Type Of Data Compromised: Emails, passwords, confidential communicationsSensitivity Of Data: High (government and critical infrastructure data)Data Exfiltration: YesPersonally Identifiable Information: Likely (emails, passwords)
FEBRUARY 2025
739Before Incident
Breach
01 Feb 2025TSI
TP-Link USA

TP-Link Potential Ban Due to Security Concerns

677After Incident
HIGH-62
TP-000022225
TP-Link, a prominent US router manufacturer with historical ties to China, faces a potential ban due to security concerns and ongoing investigations. Accusations revolve around the possibility of Chinese state-sponsored hackers compromising routers, and the company's obligation under Chinese law to provide sensitive information. This controversy has raised questions about TP-Link’s prices and market dominance, with fears that it might reflect a strategy to unfairly influence the US market. The company rebukes these concerns, highlighting its restructuring efforts, diverse manufacturing locations, and transparency with US investigators.
INCIDENT DETAILS -
TYPE
Security Concerns and Investigations
MOTIVATION
Unfair market influence and potential espionage
IMPACT
Systems Affected: RoutersBrand Reputation Impact: NegativeLegal Liabilities: Ongoing investigations and potential ban
NOVEMBER 2024
757Before Incident
Cyber Attack
01 Nov 2024TSI
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach

737After Incident
LOW-20
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection. First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion. Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks. Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection. As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
DDoS-for-Hire Botnet
MOTIVATION
Financial gain (DDoS-for-hire service)Long-term survival with low visibility
IMPACT
IoT devices (routers, cameras, gateways)Disruption of CDNs, game servers, and enterprises via volumetric DDoS attacks
DATA BREACH
Data Encryption: XOR-based encryption

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for TSI ?
?
What was TSI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was TSI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was TSI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was TSI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was TSI's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on TSI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with TSI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view TSI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?