logo

Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers

ID: e33defd3-550a-586a-ad0e-74351ffda620

STIX ID: report--e33defd3-550a-586a-ad0e-74351ffda620

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

## Executive Summary FortiGuard Labs uncovered a Nexcorium campaign that exploits a critical OS command injection (CVE-2024-3721) in TBK DVRs to deploy a multi-architecture Mirai-like botnet. The malware fetches architecture-specific "nexuscorp" binaries, uses brute-force Telnet credentials and a Huawei exploit (CVE-2017-17215) for propagation, employs multiple persistence mechanisms, deletes original binaries to hinder analysis, and coordinates large-scale DDoS operations via the C2 domain r3brqw3d.boats.top; researchers attribute activity to an emerging group labeled "Nexus Team."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.