Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers
ID: e33defd3-550a-586a-ad0e-74351ffda620
STIX ID: report--e33defd3-550a-586a-ad0e-74351ffda620
Feed Name: securityonline.info
## Executive Summary FortiGuard Labs uncovered a Nexcorium campaign that exploits a critical OS command injection (CVE-2024-3721) in TBK DVRs to deploy a multi-architecture Mirai-like botnet. The malware fetches architecture-specific "nexuscorp" binaries, uses brute-force Telnet credentials and a Huawei exploit (CVE-2017-17215) for propagation, employs multiple persistence mechanisms, deletes original binaries to hinder analysis, and coordinates large-scale DDoS operations via the C2 domain r3brqw3d.boats.top; researchers attribute activity to an emerging group labeled "Nexus Team."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
