Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721
ID: 4c318103-5660-556d-8eb4-93384b0459c9
STIX ID: report--4c318103-5660-556d-8eb4-93384b0459c9
Feed Name: Securelist by Kaspersky
Threat Score
Kaspersky observed an active Mirai-based botnet variant exploiting CVE-2024-3721 to deploy ARM32 binaries to vulnerable TBK DVR devices via a crafted POST request. The analysis details the infection vector, RC4-based string decryption, anti-VM/anti-emulation checks, and telemetry indicating widespread infections across multiple countries, and includes MD5 hashes and IP addresses as IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
