Nexus Team
Nexus Team is a relatively unknown threat actor identified by Fortinet FortiGuard Labs in connection with a Mirai-related botnet campaign targeting TBK DVR devices, specifically TBK DVR-4104 and DVR-4216, via CVE-2024-3721, an OS command injection vulnerability. The attribution is based on exploit traffic containing the custom HTTP header "X-Hacked-By: Nexus Team – Exploited By Erratic," and the actor is not described as widely known. The campaign distributes a Mirai-like malware variant named Nexcorium using a downloader shell script named "dvr," which retrieves multi-architecture Linux payloads including ARM, MIPS/MIPS R3000, and x86-64 samples with filenames beginning with "nexuscorp." Nexcorium contains Mirai-style watchdog, scanner, and attacker modules; uses XOR-decoded embedded configuration data; connects to a command-and-control server to receive commands; and is assessed to be used primarily for botnet expansion and DDoS activity. Observed propagation and post-compromise behavior include exploitation of CVE-2024-3721, brute-force Telnet attempts using hard-coded default credentials, and embedded exploitation support for CVE-2017-17215 against Huawei HG532 devices. Nexcorium establishes persistence through multiple mechanisms, including modifying /etc/inittab, updating or creating /etc/rc.local, creating a systemd service, and adding cron jobs. It also performs self-integrity checks, can replicate itself if tampering is detected, and deletes its original binary after setup to hinder analysis. The malware supports multiple DDoS attack methods, including UDP flood, TCP SYN flood, TCP ACK flood, SMTP flood, TCP PSH flood, TCP URG flood, UDP blast flood, VSE query flood, and TCP generic flood. Known associated malware and campaign identifiers directly mentioned in the reporting include Nexcorium, the downloader script "dvr," and payload names beginning with "nexuscorp."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a botnet campaign targeting IoT devices, particularly TBK digital video recorders, deploying the Nexcorium malware for persistence and DDoS activity.
Possibly linked to a campaign exploiting TBK DVR devices and outdated TP-Link routers to deploy the Nexcorium Mirai variant for botnet growth and DDoS attacks.
Operating the Nexcorium Mirai-derived botnet to compromise internet-connected DVR devices and build a large-scale DDoS botnet.
Associated with a campaign exploiting CVE-2024-3721 in TBK DVR devices to deliver the Nexcorium Mirai variant, establish persistence, brute-force Telnet services, and conduct DDoS attacks via centralized C2 infrastructure.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.