logo

Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign

ID: 6e824ed1-c20d-513a-9a32-048ba6844a10

STIX ID: report--6e824ed1-c20d-513a-9a32-048ba6844a10

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-27

...
...

FortiGuard Labs analyzed an active campaign exploiting CVE-2024-3721 in TBK DVR devices to deploy a Mirai-variant botnet called Nexcorium; the report covers the exploit (including a custom “X-Hacked-By” HTTP header), a downloader that fetches multi-architecture payloads, the malware’s XOR-decoded configuration, brute-force Telnet scanning using a hard-coded credential list, persistence methods (inittab, rc.local, systemd, cron), a range of DDoS modules, C2 infrastructure (r3brqw3d.b0ats.top and listed IPs), file hashes, and Fortinet detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.