logo

New Mirai variants target routers and DVRs in parallel campaigns

ID: 14da8ee4-313c-5374-bcfb-8d8925f5a4e4

STIX ID: report--14da8ee4-313c-5374-bcfb-8d8925f5a4e4

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Akamai and Fortinet researchers documented two Mirai-like IoT botnet campaigns: "tuxnokill" (exploiting CVE-2025-29635 and other router flaws) and "Nexcorium" (attributed to "Nexus Team" targeting DVRs via CVE-2024-3721). Both deploy multi-architecture malware with persistence mechanisms, remove trace binaries to hinder analysis, and enable compromised devices to perform DDoS attacks; active exploitation was observed via honeypots and IoCs/detection rules have been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.