Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors section9

Also known as: tracked as, casual, such as a nickname, Trojan Horse, Trojan Virus, a Permanent DoS attack, data extrusion, data theft, Permanent Denial of Service, Matthews Correlation Coefficient, Airborne malware, the client, SH, CVE, BASHLITE, Gafgyt, Lizkebab, Torlus, LizardStresser, Qbot, Bash0day, the BillGates Trojan, Qakbot, QBot, QuackBot, instruction codes, Convnets, extract features, Reasonable Suspicion

Description

Section9 is a criminal organization that exploits a wide array of CVE vulnerabilities across low‑end routers, set‑top boxes, smart TVs and other embedded devices to install persistent backdoors. The framework modularly drops distinct malware families—Mirai variants, EchoBot, Wicked, Brickerbot, VPNFilter, Tsunami, Bashlite and several custom derivatives—each capable of conducting DDoS attacks, cryptomining or ransomware payloads. Following infection the attacker escalates privileges through exploitation or configuration changes (e.g., startup scripts, SELinux policy modifications) and installs rootkits that conceal C&C traffic while self‑destroying binaries after execution. The modular approach enables Section9 to offer DDoS‑for‑hire services with packet rates exceeding 150 Mpps, to mine Monero or other cryptocurrencies on compromised hardware, and to extend reach into embedded firmware tampering and device sabotage (PDoS). Recent activity shows the deployment of ransomware that encrypts both flash storage and attached SD cards, demanding payment in cryptocurrency. The actor’s DDoS capabilities are further enhanced by fast‑flux and domain generation algorithms for C&C infrastructure, and by an extensive P2P network for lateral movement. Section9’s operational model is tightly coupled: IoT infections feed large botnets that provide a single platform for coordinated DDoS sweeps, monetisation via mining or targeted extortion. Unlike legacy RaaS operators, Section9 extends its reach to embedded firmware tampering and device sabotage (PDoS), enabling permanent denial‑of‑service of critical infrastructure nodes.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Government
Defense
Mining
Education
Non profit
Manufacturing
Media
Healthcare
Critical infrastructure
Information technology
Gaming
Food agriculture

Targeted Countries / Regions

US
VN
CN
SY
IQ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Section9 is a medium‑sophistication criminal group that emerged in mid‑2026, targeting low‑end IoT devices via widespread CVE exploitation to assemble large botnets capable of high‑rate DDoS attacks, cryptocurrency mining and ransomware deployment. The actor deploys multiple modular malware families—including Mirai derivatives, Bashlite, Tsunami—and sophisticated C&C channels such as IRC, Tor and custom P2P networks to maintain stealth while monetizing compromised gear. Their operations are driven primarily by financial gain but also involve permanent denial‑of‑service attacks on critical infrastructure.

Goals & Targeting

The strategic objective of Section9 is primarily monetary gain through a diversified monetisation portfolio—high‑rate DDoS services for clients, large‑scale cryptomining campaigns, and ransomware attacks on both individuals and organisations. The group targets sectors with high perceived value or vulnerability to disruption: financial services, government, defense, mining, education, non‑profit, manufacturing, media, healthcare, critical infrastructure and information technology. Victims are selected based on the availability of exploitable CVEs, weak authentication mechanisms (e.g., Telnet), and network connectivity that can be leveraged for distributed attacks or extortion payments. Section9’s tactics allow rapid expansion across borders—targets include the US, Vietnam, China, Syria, Iraq—suggesting a highly mobile, opportunistic posture. The actor likely prioritises devices where patching is slow or overlooked and leverages open‑source firmware or custom backdoors to maintain persistence while remaining stealthy. In addition to direct financial returns, Section9’s operations may aim to undermine trust in IoT deployments, force organisations into costly remediation or supply‑chain disruptions, and secure a foothold for future adversarial campaigns.

Enhanced Description

Key Capabilities

  • Exploits CVE vulnerabilities across a broad range of IoT devices
  • Utilizes a modular backdoor framework to distribute multiple malware families
  • Operates command-and-control channels via IRC, MySQL, Tor and other text‑based protocols
  • Executes memory‑resident payloads to evade detection
  • Conducts brute‑force credential attacks over Telnet/SSH/FTP
  • Performs mass vulnerability scanning through P2P networks
  • Deploys DDoS attacks employing UDP flood, SYN flood, TCP ACK flood, and GRE flood tactics
  • Engages in cryptocurrency mining (Monero and other coins)
  • Deletes or blocks competing malware communications and files
  • Removes host security defenses such as SELinux, firewalls, monitoring tools
  • Persists by self‑copying to system directories (/usr/bin/, /etc/init.d/, crontab @reboot)
  • Lateral movement through Bluetooth vulnerabilities (BlueBorne)

MITRE ATT&CK Tactics

Initial Access
Privilege Escalation
Execution
Persistence
Defense Evasion
Command and Control
Impact

ATT&CK Techniques

T1068
T1071
T1110
T1046
T1107
T1499
T1523
T1190
T1078

Software / Tooling

Mirai
Bashlite
Tsunami
EchoBot
Wicked
BrickerBot
VPNFilter
Satori
ZHtrap
Persirai
Gitpaste-12
SoraLOADER
Omni
Owari
cpuminer
Miori
Sora
Muhstik
Setag
Blueborne
APEP
Hajime
Darlloz

Campaigns & Victims

Section9 operates in rapid, modular bursts—initial infection through known CVE exploits, followed by the deployment of a specific malware family tailored to the device type. Botnet size swells within days as P2P networks propagate backdoors across globally dispersed IoT devices. Victims range from small businesses with legacy firmware to critical infrastructure nodes lacking hardened security controls. High‑rate DDoS campaigns are launched on demand; cryptomining revenue streams grow steadily over weeks, while ransomware is deployed opportunistically against valuable or poorly patched systems. Notable operations include mid‑2026 DDoS sweeps exceeding 150 Mpps against financial sector endpoints and a multi‑month Monero mining operation that exploited a widespread router CVE.

IOC Patterns

  • CVE identifiers
  • Open TCP port numbers (80,8080,81,8291)
  • Tor C&C server usage
  • Memory-only execution flag
  • File deletion patterns
  • P2P network scanning signatures
  • IP addresses used in Telnet brute‑force attempts
  • IRC channel or server hostnames/IPs
  • MySQL server connection strings as C&C coordinates
  • Bluetooth MAC addresses of targeted devices

Recommended Actions

  • Patch or mitigate known CVE vulnerabilities in IoT devices as soon as patches are released
  • Disable unused protocols and close open TCP ports (e.g., 80, 8080, 81, 8291) on all networked devices
  • Implement strong default credentials or enforce password changes for IoT device administration
  • Use firewalls or access control lists to restrict outbound traffic from the network to known C&C endpoints
  • Deploy intrusion detection/prevention systems capable of detecting high‑rate UDP/SYN/TCP ACK/GRE traffic indicative of DDoS floods
  • Patch devices exposed to CVE-2018-20062, CVE-2017-17215, CVE-2018-10561, CVE-2022-0543 and other listed vulnerabilities immediately
  • Disable or secure Telnet service on all IoT devices
  • Block inbound/outbound traffic over IRC ports (6660–6669) unless explicitly required
  • Deploy network monitoring for signs of DDoS traffic
  • Apply firewall rules that limit outbound connections to known malicious IP ranges or random IP addresses used by Bashlite family
  • Enable Bluetooth security features and monitor for lateral movement via BlueBorne

Suggested Tags

IoT
DDoS
Malware
Botnet
Mirai Variant
CVE Exploit
Cryptomining
P2P Scanning
Memory‑only Malware
Defense Evasion
Tor C&C
Remote Code Execution
Telnet Brute Force
IRC Command And Control
Bluetooth Vulnerability
Crypto Miner

Confidence Assessment

The data on Section9 provides high confidence regarding its modular IoT exploitation, DDoS capabilities, and use of multiple malware families derived from Mirai. Confidence is moderate concerning the extent of ransomware deployment and precise operational tempo beyond July 2026 due to limited publicly available incident reports and reliance on brief intelligence slices. Key gaps remain in definitive supply‑chain attribution, long‑term financial impact figures, and the full spectrum of target sectors impacted outside the reported high‑profile campaigns.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Discovery
1 technique
Privilege Escalation
1 technique
Stealth
1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

Intel Summary

10

Techniques

56

Tools

20

Campaigns

39

IOCs

0

Observed Data

8

Tactics

Tags

ransomware-as-a-service
IoT
DDoS-for-hire
Mirai-variant
rootkit
backdoor
credential-brute-force
CVE-exploitation
DNS-spoofing
fast‑flux
P2P-botnet
cryptocurrency-mining
financial-threat
criminal-organization
initial-access
defense-evasion
DDoS
Malware
Botnet
Mirai Variant
CVE Exploit
Cryptomining
P2P Scanning
Memory‑only Malware
Defense Evasion
Tor C&C
Remote Code Execution
Telnet Brute Force
IRC Command And Control
Bluetooth Vulnerability
Crypto Miner

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jul 26, 2026
Last Seen
Jul 30, 2026
Added
Jul 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.