logo

New Mirai Botnet Variant ‘Broadside’ Actively Attacking Users in the Wild

ID: 759fd856-7a27-5184-9114-40da3beaf6e0

STIX ID: report--759fd856-7a27-5184-9114-40da3beaf6e0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cydome analysts identified "Broadside," a sophisticated Mirai variant actively exploiting CVE-2024-3721 in TBK DVRs used on maritime vessels; the malware installs via crafted HTTP POST requests, runs in-memory across ARM/MIPS/x86/PowerPC, and uses a hardcoded C2 "Magic Header" (0x36694201). Broadside includes dual process-monitoring modes (Netlink "Smart Mode" and aggressive "Panic Mode"), a process-killer module, credential harvesting from /etc/passwd and /etc/shadow, and persistent, polymorphic high-rate UDP flood capabilities that can saturate satellite uplinks and enable lateral movement within flat shipboard networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.