logo

Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware

ID: 574b9254-6194-5081-82d0-60a621a1eac4

STIX ID: report--574b9254-6194-5081-82d0-60a621a1eac4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Mirai-derived botnet named Nexcorium is actively exploiting TBK DVR models (CVE-2024-3721) and legacy TP-Link routers (CVE-2017-17215) to recruit devices into a DDoS-capable botnet; the campaign leverages unauthenticated RCE via a vulnerable endpoint, architecture-specific downloader binaries, persistence mechanisms (watchdog, self-copying with FNV-1a checks), and aggressive Telnet brute-forcing with default credentials, creating a large, hard-to-filter attack infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.