logo

New botnet exploits vulnerabilities in NVRs, TP-Link routers

ID: 8e9a6fda-3327-5c9b-a6dc-eced91046e5b

STIX ID: report--8e9a6fda-3327-5c9b-a6dc-eced91046e5b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-24

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A Mirai-derived botnet campaign active since at least September is exploiting an unpatched RCE in DigiEver DS-2105 Pro NVRs (via /cgi-bin/cgi_main.cgi command injection) and known router flaws (TP-Link CVE-2023-1389 and Teltonika CVE-2018-17532) to install multi-architecture malware (using XOR/ChaCha20 obfuscation), achieve persistence via cron jobs, and perform DDoS/spread operations; Akamai published IoCs and YARA rules to detect the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.