logo

Nexcorium Mirai Variant Weaponises TBK DVR Vulnerability in Fresh IoT Botnet Push

ID: 298ea9f3-c2de-5b50-8f85-e8a27ec5cb9b

STIX ID: report--298ea9f3-c2de-5b50-8f85-e8a27ec5cb9b

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-18

Date Updated: 2026-04-22

Author: Divya

...
...

Nexcorium is a Mirai-family IoT botnet actively exploiting CVE-2024-3721 in TBK DVRs (and leveraging CVE-2017-17215 and default-password Telnet brute-force) to deliver a multi-architecture payload that establishes persistence and receives commands to execute diverse, large-scale DDoS attacks; FortiGuard Labs observed a distinctive "X-Hacked-By:Nexus Team – Exploited By Erratic" HTTP header linking the activity to a suspected Nexus Team actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.