Also known as: tracked as, casual, such as a nickname, Trojan Horse, Trojan Virus, a Permanent DoS attack, data extrusion, data theft, Permanent Denial of Service, Matthews Correlation Coefficient, Airborne malware, the client, SH, CVE, BASHLITE, Gafgyt, Lizkebab, Torlus, LizardStresser, Qbot, Bash0day, the BillGates Trojan, Qakbot, QBot, QuackBot, instruction codes, Convnets, extract features, Reasonable Suspicion
Section9 is a criminal organization that exploits a wide array of CVE vulnerabilities across low‑end routers, set‑top boxes, smart TVs and other embedded devices to install persistent backdoors. The framework modularly drops distinct malware families—Mirai variants, EchoBot, Wicked, Brickerbot, VPNFilter, Tsunami, Bashlite and several custom derivatives—each capable of conducting DDoS attacks, cryptomining or ransomware payloads. Following infection the attacker escalates privileges through exploitation or configuration changes (e.g., startup scripts, SELinux policy modifications) and installs rootkits that conceal C&C traffic while self‑destroying binaries after execution. The modular approach enables Section9 to offer DDoS‑for‑hire services with packet rates exceeding 150 Mpps, to mine Monero or other cryptocurrencies on compromised hardware, and to extend reach into embedded firmware tampering and device sabotage (PDoS). Recent activity shows the deployment of ransomware that encrypts both flash storage and attached SD cards, demanding payment in cryptocurrency. The actor’s DDoS capabilities are further enhanced by fast‑flux and domain generation algorithms for C&C infrastructure, and by an extensive P2P network for lateral movement. Section9’s operational model is tightly coupled: IoT infections feed large botnets that provide a single platform for coordinated DDoS sweeps, monetisation via mining or targeted extortion. Unlike legacy RaaS operators, Section9 extends its reach to embedded firmware tampering and device sabotage (PDoS), enabling permanent denial‑of‑service of critical infrastructure nodes.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Section9 is a medium‑sophistication criminal group that emerged in mid‑2026, targeting low‑end IoT devices via widespread CVE exploitation to assemble large botnets capable of high‑rate DDoS attacks, cryptocurrency mining and ransomware deployment. The actor deploys multiple modular malware families—including Mirai derivatives, Bashlite, Tsunami—and sophisticated C&C channels such as IRC, Tor and custom P2P networks to maintain stealth while monetizing compromised gear. Their operations are driven primarily by financial gain but also involve permanent denial‑of‑service attacks on critical infrastructure.
Goals & Targeting
The strategic objective of Section9 is primarily monetary gain through a diversified monetisation portfolio—high‑rate DDoS services for clients, large‑scale cryptomining campaigns, and ransomware attacks on both individuals and organisations. The group targets sectors with high perceived value or vulnerability to disruption: financial services, government, defense, mining, education, non‑profit, manufacturing, media, healthcare, critical infrastructure and information technology. Victims are selected based on the availability of exploitable CVEs, weak authentication mechanisms (e.g., Telnet), and network connectivity that can be leveraged for distributed attacks or extortion payments. Section9’s tactics allow rapid expansion across borders—targets include the US, Vietnam, China, Syria, Iraq—suggesting a highly mobile, opportunistic posture. The actor likely prioritises devices where patching is slow or overlooked and leverages open‑source firmware or custom backdoors to maintain persistence while remaining stealthy. In addition to direct financial returns, Section9’s operations may aim to undermine trust in IoT deployments, force organisations into costly remediation or supply‑chain disruptions, and secure a foothold for future adversarial campaigns.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Section9 operates in rapid, modular bursts—initial infection through known CVE exploits, followed by the deployment of a specific malware family tailored to the device type. Botnet size swells within days as P2P networks propagate backdoors across globally dispersed IoT devices. Victims range from small businesses with legacy firmware to critical infrastructure nodes lacking hardened security controls. High‑rate DDoS campaigns are launched on demand; cryptomining revenue streams grow steadily over weeks, while ransomware is deployed opportunistically against valuable or poorly patched systems. Notable operations include mid‑2026 DDoS sweeps exceeding 150 Mpps against financial sector endpoints and a multi‑month Monero mining operation that exploited a widespread router CVE.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Section9 provides high confidence regarding its modular IoT exploitation, DDoS capabilities, and use of multiple malware families derived from Mirai. Confidence is moderate concerning the extent of ransomware deployment and precise operational tempo beyond July 2026 due to limited publicly available incident reports and reliance on brief intelligence slices. Key gaps remain in definitive supply‑chain attribution, long‑term financial impact figures, and the full spectrum of target sectors impacted outside the reported high‑profile campaigns.
Section9: ****.com.pa
Ransomware attack attributed to Section9. | Country: PA | Sector: Not Found | TRAVEL | Source: https://www.ransomware.live/id/KioqKi5jb20ucGFAU2VjdGlvbjk=
Jul 29, 2026
TLP:CLEARSection9: ****.com.mc
Ransomware attack attributed to Section9. | Country: MC | Sector: Hospitality | TRAVEL & TOURISM | Source: https://www.ransomware.live/id/KioqKi5jb20ubWNAU2VjdGlvbjk=
Jul 26, 2026
TLP:CLEARSection9: *****.ind.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Agriculture and Food Production | AGRICULTURE | Source: https://www.ransomware.live/id/KioqKiouaW5kLmJyQFNlY3Rpb245
Jul 26, 2026
TLP:CLEARSection9: **********
Ransomware attack attributed to Section9. | Sector: Technology | CYBERSECURITY | Source: https://www.ransomware.live/id/KioqKioqKioqKkBTZWN0aW9uOQ==
Jul 26, 2026
TLP:CLEARSection9: *****.com.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Financial Services | FINTECH | Source: https://www.ransomware.live/id/KioqKiouY29tLmJyQFNlY3Rpb245
Jul 26, 2026
TLP:CLEARSection9: ****.com.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Technology | TELECOM | Source: https://www.ransomware.live/id/KioqKi5jb20uYnJAU2VjdGlvbjk=
Jul 26, 2026
TLP:CLEARSection9: ****.com
Ransomware attack attributed to Section9. | Country: BE | Sector: Manufacturing | INDUSTRY | Source: https://www.ransomware.live/id/KioqKi5jb21AU2VjdGlvbjk=
Jul 26, 2026
TLP:CLEARSection9: *******.com
Ransomware attack attributed to Section9. | Country: US | Sector: Retail & E-Commerce | ECOMMERCE | Source: https://www.ransomware.live/id/KioqKioqKi5jb21AU2VjdGlvbjk=
Jul 26, 2026
TLP:CLEARSection9: ********.com.jp
Ransomware attack attributed to Section9. | Country: JP | Sector: Technology | SOFTWARE | Source: https://www.ransomware.live/id/KioqKioqKiouY29tLmpwQFNlY3Rpb245
Jul 26, 2026
TLP:CLEARSection9: ******.com.se
Ransomware attack attributed to Section9. | Country: SE | Sector: Healthcare | HEALTHCARE | Source: https://www.ransomware.live/id/KioqKioqLmNvbS5zZUBTZWN0aW9uOQ==
Jul 26, 2026
TLP:CLEARSection9: ******.net.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Financial Services | TAX | Source: https://www.ransomware.live/id/KioqKioqLm5ldC5ickBTZWN0aW9uOQ==
Jul 26, 2026
TLP:CLEARSection9: ******.com.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Other | MEDIA | Source: https://www.ransomware.live/id/KioqKioqLmNvbS5ickBTZWN0aW9uOQ==
Jul 26, 2026
TLP:CLEARSection9: ********.com.br
Ransomware attack attributed to Section9. | Country: BR | Sector: Not Found | MINING | Source: https://www.ransomware.live/id/KioqKioqKiouY29tLmJyQFNlY3Rpb245
Jul 26, 2026
TLP:CLEARSection9: *****.com.pt
Ransomware attack attributed to Section9. | Country: PT | Sector: Education | UNIVERSITY | Source: https://www.ransomware.live/id/KioqKiouY29tLnB0QFNlY3Rpb245
Jul 26, 2026
TLP:CLEARSection9: ****.fr
Ransomware attack attributed to Section9. | Country: FR | Sector: Retail & E-Commerce | RETAIL | Source: https://www.ransomware.live/id/KioqKi5mckBTZWN0aW9uOQ==
Jul 26, 2026
TLP:CLEARSection9: ********.com
Ransomware attack attributed to Section9. | Country: US | Sector: Other | NEWS | Source: https://www.ransomware.live/id/KioqKioqKiouY29tQFNlY3Rpb245
Jul 26, 2026
TLP:CLEARNo observed data linked yet.
10
Techniques
56
Tools
20
Campaigns
39
IOCs
0
Observed Data
8
Tactics