Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
ID: 92bf310e-8eb3-54b8-843e-430cfb4ba22b
STIX ID: report--92bf310e-8eb3-54b8-843e-430cfb4ba22b
Feed Name: The Hacker News
Fortinet FortiGuard Labs and Unit 42 report that threat actors are actively exploiting CVE-2024-3721 in TBK DVR devices to deploy a Mirai-like botnet called Nexcorium, which uses additional exploits (including CVE-2017-17215), telnet brute-force with hard-coded credentials, multi-architecture payloads, and persistence mechanisms to launch UDP/TCP/SMTP DDoS attacks; Unit 42 also observed automated scans targeting CVE-2023-33538 in end-of-life TP‑Link routers, highlighting continued risk from unpatched IoT devices and default credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
