logo

Attackers Exploit DVR Command Injection Flaw to Deploy Mirai-Based Botnet

ID: d3fbfb43-524b-56aa-9370-926a39d4d583

STIX ID: report--d3fbfb43-524b-56aa-9370-926a39d4d583

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

...
...

FortiGuard Labs observed a Nexcorium campaign leveraging a command injection vulnerability (CVE-2024-3721) in TBK DVRs to download and execute a multi-architecture Mirai-based botnet (ARM, MIPS, x86-64). The malware uses XOR-encoded configuration containing C2 details and credentials for brute force, modifies startup files and cron jobs for persistence, includes legacy exploits like CVE-2017-17215 to expand reach, and supports a range of DDoS methods controlled via centralized C2; defenders are advised to prioritize IoT hygiene, agentless discovery, credential and firmware management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.