logo

Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations

ID: a35f57f8-eb80-5064-9fde-149f7dfba6ad

STIX ID: report--a35f57f8-eb80-5064-9fde-149f7dfba6ad

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-18

Date Updated: 2026-04-21

Author: Dhivya

...
...

FortiGuard Labs identified Nexcorium, a Mirai-like botnet actively exploiting CVE-2024-3721 in TBK DVR-4104 and DVR-4216 devices to install multi-architecture payloads (ARM, MIPS, x86-64) and build a DDoS botnet; the campaign (attributed to the 'Nexus Team') leverages legacy exploits (including CVE-2017-17215), Telnet brute-forcing, modular Mirai components, multiple persistence mechanisms, and communicates with C2 to launch varied flood attacks—mitigations recommended include patching CVE-2024-3721, replacing default credentials, and network segmentation of vulnerable IoT endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.