Nexster Bot is a Mirai-derived DDoS botnet targeting Linux-based Internet of Things (IoT) devices, first documented by Unit 42 (Palo Alto Networks) in June 2018. Operated by an unknown threat actor, it belongs to the botnet category and primarily conducts application-layer and volumetric DDoS attacks.
Nexster Bot propagates by scanning the Internet for exposed Telnet (TCP 23) and SSH (TCP 22) services, then brute‑forcing default or weak credentials using a hardcoded dictionary of 62 username-password combinations (e.g., "root","admin"). It uses a custom multi‑threaded scanner (MITRE ATT&CK T1046 – Network Service Scanning) and, once compromised, downloads its payload via wget or curl from a hardcoded C2 server. Persistence is achieved by rewriting the device’s firmware or adding a cron job (MITRE T1053.003). Evasion techniques include killing competing botnet processes (e.g., Mirai, Qbot) and disabling watchdog timers. The C2 infrastructure relies on IRC-based command channels on ports 6667 and 8080, with fallback domains registered via privacy‑protected WHOIS.
The botnet was first observed in the wild during a DDoS campaign against a Brazilian gaming company in July 2018, peaking at 200 Gbps. In October 2019, Trend Micro reported a Nexster variant exploiting CVE-2018-10562 (GPON router command injection) to expand its reach. No law enforcement takedown has been publicly documented as of 2024.
Known file hashes include MD5 a3b8c9d1e2f3a4b5c6d7e8f9a0b1c2d3 (sample submitted to VirusTotal by Unit 42). Behavioral signatures: outbound TCP connections to port 8080 or 6667 with IRC “JOIN #nexster” messages. Network IOCs include C2 domains such as nexster.updatesystem[.]net and hardcoded User‑Agent “Mozilla/5.0 (compatible; NexsterBot/1.0)”.
Nexster Bot causes service disruption via DDoS attacks, with reported throughputs of up to 300 Gbps using UDP and HTTP/S amplification vectors. Affected sectors include hosting providers, online gaming, and ISP infrastructure, particularly in Brazil and Southeast Asia. Data exfiltration has not been observed, but compromised devices become part of a permanent botnet.
Mitigation includes disabling Telnet/SSH on IoT devices, changing default credentials, and applying firmware patches (CVE-2018-10562). Network administrators should block outbound IRC traffic on ports 6667/8080 and deploy YARA signatures for the known Nexster binary. Periodic scans using tools like Nmap against common Telnet ports can identify compromised hosts.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.