Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Nexus Zeta

Description

Nexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP related exploits, CVE-2014–8361 and CVE-2017–17215 in his Satori botnet project. A third SOAP exploit, TR-069 bug has also been observed previously in IoT botnets. This makes EDB 38722 the fourth SOAP related exploit which is discovered in the wild by IoT botnets.

AI Analysis

· 1 week ago

Executive Summary

Nexus Zeta is a criminal threat actor actively exploiting SOAP-related vulnerabilities in IoT devices to deploy botnets, with a focus on router and network equipment vulnerabilities. Their Satori botnet has previously leveraged CVE-2014–8361, CVE-2017–17215, and the TR-069 bug, with recent activity linked to EDB-38722. Their operations involve persistent infrastructure use and targeted IoCs, including suspicious domains and URLs.

Goals & Targeting

Nexus Zeta's primary objective appears to be financial gain through botnet monetization, likely via DDoS services, data exfiltration, or ransomware deployment. They target sectors with high concentrations of IoT devices, particularly in telecommunications, manufacturing, and small-to-midsize enterprises relying on legacy network equipment. Their focus on SOAP-based exploits in routers and network devices indicates a strategic interest in compromising systems with weak patch management practices, enabling long-term infrastructure control and large-scale botnet operations.

Enhanced Description

Nexus Zeta has established a pattern of exploiting SOAP-based vulnerabilities in IoT devices, particularly in router and network equipment, to compromise systems and deploy botnets. Their Satori botnet project has historically utilized multiple SOAP exploits, including CVE-2014–8361 and CVE-2017–17215, and their activities were previously observed in IoT botnets leveraging the TR-069 bug. The recent discovery of EDB-38722, a fourth SOAP-related exploit linked to IoT botnets, underscores their continued focus on exploiting vulnerabilities in consumer and enterprise-grade networking hardware. The threat actor's operational infrastructure includes domains such as 'nexusiotsolutions.net' and URLs like 'http://purenetworks.com/HNAP1/GetDeviceSettings,' which are associated with command-and-control (C2) communication and initial compromise vectors. Their tactics suggest a preference for remote code execution via unpatched vulnerabilities, followed by lateral movement and persistent malware installation.

Key Capabilities

  • Exploitation of SOAP-based vulnerabilities in IoT devices
  • Deployment and management of large-scale botnets (e.g., Satori)
  • Use of C2 infrastructure via malicious domains and URLs
  • Custom development of exploit code for router-specific vulnerabilities
  • Persistence mechanisms through compromised device firmware

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Exfiltration

ATT&CK Techniques

T1210.001 - Exploit Public-Facing Application (SOAP-based)
T1573.003 - DNS Tunneling (for C2)
T1102 - Substitute Legitimate Software
T1059.003 - Command and Scripting Interpreter: PowerShell
T1060 - Exploit Public-Facing Application

Software / Tooling

Satori botnet
Custom IoT malware leveraging TR-069 protocol
Exploit code targeting EDB-38722 vulnerability

Campaigns & Victims

Nexus Zeta operates with a high operational tempo, frequently updating botnet infrastructure and exploiting newly disclosed vulnerabilities. Their campaigns, such as the Masuta botnet linked to Satori creators, demonstrate a focus on IoT device compromise, often targeting consumer-grade routers and network appliances. Notable past operations include weaponizing previously unpatched SOAP exploits, with a clear strategy of repurposing known vulnerabilities across multiple botnet iterations. Their campaigns typically involve multi-stage attacks, starting with initial compromise via unpatched devices, followed by lateral movement and C2 establishment.

IOC Patterns

  • Spear-phishing with malicious URLs targeting network administrators
  • C2 communication over DNS using domain fronting techniques
  • Staging infrastructure on compromised IoT device IP ranges
  • Exploit payloads targeting SOAP endpoints in routers

Recommended Actions

  • Patch all network devices with known SOAP vulnerability exposures (e.g., CVE-2014–8361, CVE-2017–17215)
  • Monitor DNS traffic for anomalous domain queries related to 'nexusiotsolutions.net' or similar malicious domains
  • Implement network segmentation to isolate IoT devices from critical systems
  • Deploy intrusion detection systems to identify payloads targeting TR-069 or SOAP endpoints
  • Conduct regular vulnerability assessments for legacy network equipment

Suggested Tags

APT
botnet
IoT
exploit-kit
telecom-sector
router-exploit

Confidence Assessment

High confidence in Nexus Zeta's activities based on observed exploit patterns, linked campaigns, and confirmed IoCs. However, gaps exist in fully mapping their command-and-control infrastructure and identifying all associated malicious domains. The actor's use of compromised IoT devices for C2 may obscure their true operational scale, requiring further OSINT and honeypot analysis for complete attribution.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
DDoS
APT
botnet
IoT
exploit-kit
telecom-sector
router-exploit

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.