logo

Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721

ID: 4c318103-5660-556d-8eb4-93384b0459c9

STIX ID: report--4c318103-5660-556d-8eb4-93384b0459c9

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-06-06

Date Updated: 2026-04-29

Author: Anderson Leite

...
...

Kaspersky observed an active Mirai-based botnet variant exploiting CVE-2024-3721 to deploy ARM32 binaries to vulnerable TBK DVR devices via a crafted POST request. The analysis details the infection vector, RC4-based string decryption, anti-VM/anti-emulation checks, and telemetry indicating widespread infections across multiple countries, and includes MD5 hashes and IP addresses as IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.