logo

Nexcorium Mirai variant exploits TBK DVR flaw to launch DDoS attacks

ID: f811c032-020d-5750-ac5e-ea54624ab5dc

STIX ID: report--f811c032-020d-5750-ac5e-ea54624ab5dc

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Fortinet researchers observed a Mirai-derived malware family called Nexcorium actively exploiting CVE-2024-3721 in TBK DVRs (and targeting outdated TP-Link routers) to deploy multi-architecture binaries and grow a DDoS botnet. Nexcorium uses XOR-encoded configuration, embedded exploits (including CVE-2017-17215), brute-force Telnet credential lists, and multiple persistence mechanisms to maintain long-term access and conduct UDP/TCP flood attacks; the campaign shows real-world exploitation and reuse of known IoT vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.