Nexcorium Mirai Variant Weaponises TBK DVR Vulnerability in Fresh IoT Botnet Push
ID: 298ea9f3-c2de-5b50-8f85-e8a27ec5cb9b
STIX ID: report--298ea9f3-c2de-5b50-8f85-e8a27ec5cb9b
Feed Name: GBHackers
Threat Score
Nexcorium is a Mirai-family IoT botnet actively exploiting CVE-2024-3721 in TBK DVRs (and leveraging CVE-2017-17215 and default-password Telnet brute-force) to deliver a multi-architecture payload that establishes persistence and receives commands to execute diverse, large-scale DDoS attacks; FortiGuard Labs observed a distinctive "X-Hacked-By:Nexus Team – Exploited By Erratic" HTTP header linking the activity to a suspected Nexus Team actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
