Nexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP related exploits, CVE-2014–8361 and CVE-2017–17215 in his Satori botnet project. A third SOAP exploit, TR-069 bug has also been observed previously in IoT botnets. This makes EDB 38722 the fourth SOAP related exploit which is discovered in the wild by IoT botnets.
Executive Summary
Nexus Zeta is a criminal threat actor actively exploiting SOAP-related vulnerabilities in IoT devices to deploy botnets, with a focus on router and network equipment vulnerabilities. Their Satori botnet has previously leveraged CVE-2014–8361, CVE-2017–17215, and the TR-069 bug, with recent activity linked to EDB-38722. Their operations involve persistent infrastructure use and targeted IoCs, including suspicious domains and URLs.
Goals & Targeting
Nexus Zeta's primary objective appears to be financial gain through botnet monetization, likely via DDoS services, data exfiltration, or ransomware deployment. They target sectors with high concentrations of IoT devices, particularly in telecommunications, manufacturing, and small-to-midsize enterprises relying on legacy network equipment. Their focus on SOAP-based exploits in routers and network devices indicates a strategic interest in compromising systems with weak patch management practices, enabling long-term infrastructure control and large-scale botnet operations.
Enhanced Description
Nexus Zeta has established a pattern of exploiting SOAP-based vulnerabilities in IoT devices, particularly in router and network equipment, to compromise systems and deploy botnets. Their Satori botnet project has historically utilized multiple SOAP exploits, including CVE-2014–8361 and CVE-2017–17215, and their activities were previously observed in IoT botnets leveraging the TR-069 bug. The recent discovery of EDB-38722, a fourth SOAP-related exploit linked to IoT botnets, underscores their continued focus on exploiting vulnerabilities in consumer and enterprise-grade networking hardware. The threat actor's operational infrastructure includes domains such as 'nexusiotsolutions.net' and URLs like 'http://purenetworks.com/HNAP1/GetDeviceSettings,' which are associated with command-and-control (C2) communication and initial compromise vectors. Their tactics suggest a preference for remote code execution via unpatched vulnerabilities, followed by lateral movement and persistent malware installation.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nexus Zeta operates with a high operational tempo, frequently updating botnet infrastructure and exploiting newly disclosed vulnerabilities. Their campaigns, such as the Masuta botnet linked to Satori creators, demonstrate a focus on IoT device compromise, often targeting consumer-grade routers and network appliances. Notable past operations include weaponizing previously unpatched SOAP exploits, with a clear strategy of repurposing known vulnerabilities across multiple botnet iterations. Their campaigns typically involve multi-stage attacks, starting with initial compromise via unpatched devices, followed by lateral movement and C2 establishment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Nexus Zeta's activities based on observed exploit patterns, linked campaigns, and confirmed IoCs. However, gaps exist in fully mapping their command-and-control infrastructure and identifying all associated malicious domains. The actor's use of compromised IoT devices for C2 may obscure their true operational scale, requiring further OSINT and honeypot analysis for complete attribution.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
2
IOCs
0
Observed Data
0
Tactics