Meris
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat activity described in the source material centers on operators of Internet of Things botnets that are used to launch distributed denial‑of‑service attacks. The material does not assign a specific alias or name to this activity, referring instead to the broader phenomenon of IoT‑based botnets. No public attribution to a particular state‑sponsored group or criminal consortium is provided in the source. Consequently, the actor is best described generically as IoT botnet operators whose primary observable activity is the generation of large‑scale traffic floods.
According to the source, the activity is characterized by distributed denial‑of‑service attacks intended to disrupt the availability of online services. The text does not specify particular industry sectors or geographic regions that are preferentially targeted, nor does it ascribe financial or espionage motives to the actors. Instead, the discussion emphasizes the disruptive nature of the traffic floods and notes that defenders have worked to disrupt the infrastructure abused by these botnets. This indicates that the observable objective is service disruption rather than profit or espionage.
The tactics described involve the compromise of Internet of Things devices to build botnets that generate volumetric traffic. The source mentions that these botnets are assembled by exploiting vulnerabilities in IoT hardware, but it does not name any specific malware families, exploit kits, or initial access vectors. It also notes that the infrastructure supporting these botnets has been a focus of disruption efforts by groups such as the Cambridge University Cybercrime Centre, referencing comments from Richard Clayton. No further detail on tooling, command‑and‑control structures, or post‑exploitation tools is provided.
In terms of publicly reported operations, the source cites the general prevalence of IoT botnet‑driven DDoS attacks as the context for the discussion, highlighting that the internet community has improved its ability to counter such threats by attacking the underlying infrastructure. No individual campaign, dated operation, or named malware family is singled out in the text. Consequently, the profile can only note that the actors have been observed conducting large‑scale disruption attacks using compromised IoT devices, as illustrated by the broader discussion of botnet‑based DDoS activity in the article.
Incidents
Attributed incidents are available to members.
2 incidents