logo

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

ID: 92bf310e-8eb3-54b8-843e-430cfb4ba22b

STIX ID: report--92bf310e-8eb3-54b8-843e-430cfb4ba22b

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-04-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Fortinet FortiGuard Labs and Unit 42 report that threat actors are actively exploiting CVE-2024-3721 in TBK DVR devices to deploy a Mirai-like botnet called Nexcorium, which uses additional exploits (including CVE-2017-17215), telnet brute-force with hard-coded credentials, multi-architecture payloads, and persistence mechanisms to launch UDP/TCP/SMTP DDoS attacks; Unit 42 also observed automated scans targeting CVE-2023-33538 in end-of-life TP‑Link routers, highlighting continued risk from unpatched IoT devices and default credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.