logo

New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks

ID: c1f37bca-8e21-5e6e-8d7d-85ca5a438336

STIX ID: report--c1f37bca-8e21-5e6e-8d7d-85ca5a438336

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Fortinet’s FortiGuard Labs discovered Nexcorium, a Mirai-style IoT botnet malware actively targeting DVR video recording devices (especially TBK DVR-4104 and DVR-4216) by exploiting CVE-2024-3721 and other known vulnerabilities; Nexcorium is multi-architecture, persists across reboots, spreads via brute-force using a large hardcoded password list, and is used to assemble DDoS-capable botnets with attribution to a group calling itself Nexus Team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.