logo

TBK DVR Vulnerability CVE-2024-3721 Exploited to Spread Nexcorium DDoS Malware

ID: ebb1f076-887b-5daa-9a54-aa0fa9f894e0

STIX ID: report--ebb1f076-887b-5daa-9a54-aa0fa9f894e0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

FortiGuard Labs reports active exploitation of CVE-2024-3721 in TBK DVR devices to deploy "Nexcorium", a Mirai-based multi-architecture botnet that uses a remote command-injection vector to install a multi-arch payload via a 'dvr' installer, employs persistence (inittab, rc.local, systemd service, cron), brute-force Telnet login, and offers diverse DDoS capabilities; observed IoCs include the custom HTTP header 'X-Hacked-By:Nexus Team – Exploited By Erratic' and C2 domain r3brqw3d.b0ats.top. Organizations are advised to patch affected devices, disable unnecessary services like Telnet, and monitor network traffic for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.