Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations
ID: a35f57f8-eb80-5064-9fde-149f7dfba6ad
STIX ID: report--a35f57f8-eb80-5064-9fde-149f7dfba6ad
Feed Name: cybersecurityNews.com
FortiGuard Labs identified Nexcorium, a Mirai-like botnet actively exploiting CVE-2024-3721 in TBK DVR-4104 and DVR-4216 devices to install multi-architecture payloads (ARM, MIPS, x86-64) and build a DDoS botnet; the campaign (attributed to the 'Nexus Team') leverages legacy exploits (including CVE-2017-17215), Telnet brute-forcing, modular Mirai components, multiple persistence mechanisms, and communicates with C2 to launch varied flood attacks—mitigations recommended include patching CVE-2024-3721, replacing default credentials, and network segmentation of vulnerable IoT endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
