New Mirai variants target routers and DVRs in parallel campaigns
ID: 14da8ee4-313c-5374-bcfb-8d8925f5a4e4
STIX ID: report--14da8ee4-313c-5374-bcfb-8d8925f5a4e4
Feed Name: Help Net Security
Threat Score
Akamai and Fortinet researchers documented two Mirai-like IoT botnet campaigns: "tuxnokill" (exploiting CVE-2025-29635 and other router flaws) and "Nexcorium" (attributed to "Nexus Team" targeting DVRs via CVE-2024-3721). Both deploy multi-architecture malware with persistence mechanisms, remove trace binaries to hinder analysis, and enable compromised devices to perform DDoS attacks; active exploitation was observed via honeypots and IoCs/detection rules have been published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
