Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureembedded-device-vulnerabilityactively-exploited-vulnerabilitycommand-and-control-method

Broadside Mirai Botnet Targets TBK DVRs in Maritime Logistics

Updated 3mo agoFirst seen Dec 9, 20252 sources

A new Mirai botnet variant known as Broadside has been identified targeting vulnerable TBK Vision digital video recorders (DVRs) used extensively in the maritime logistics sector. Researchers from Cydome discovered that Broadside exploits the command injection vulnerability CVE-2024-3721 in TBK DVR-4104 and DVR-4216 devices, allowing attackers to hijack these systems. The botnet employs advanced techniques such as a custom C2 protocol, a unique Magic Header, and a process-killer module to maintain persistence and evade detection. In addition to supporting UDP-based DDoS attacks, Broadside is capable of stealing sensitive files like /etc/passwd and /etc/shadow, enabling privilege escalation and lateral movement within compromised networks.

The maritime sector is particularly vulnerable due to widespread use of legacy, unpatched systems and a general lack of onboard cybersecurity personnel or monitoring. The Broadside campaign has been active for months, with fluctuating activity observed by researchers. Attackers leverage a mass loader to execute multi-architecture payloads in memory and wipe traces, making detection and remediation challenging. The ongoing exploitation of CVE-2024-3721 by Broadside and other botnets highlights the urgent need for improved security practices and patch management in maritime environments to prevent further compromise and disruption.

Share:
Broadside Mirai Botnet Targets TBK DVRs in Maritime Logistics
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 9, 20257mo ago

Researchers warn of large exposed attack surface for vulnerable DVRs

Reporting on the Broadside activity highlighted that more than 50,000 internet-exposed DVR devices could be targeted through CVE-2024-3721. The warning underscored the scale of potential risk to maritime and other organizations using the affected hardware.

Dec 8, 20257mo ago

Cydome publishes Broadside findings and indicators of compromise

Researchers at Cydome disclosed the Broadside campaign and released indicators of compromise to help maritime operators detect and mitigate infections. They warned that legacy and unpatched systems in maritime environments make the sector especially vulnerable and recommended patching, network segregation, and updated monitoring.

Broadside campaign targets maritime logistics sector

A Mirai-based botnet variant dubbed Broadside was identified actively targeting maritime logistics organizations through compromised TBK DVR devices. The malware used custom TCP command-and-control, payload polymorphism, process-killing and Netlink-based persistence, and credential theft to support DDoS activity, lateral movement, and potential disruption of vessel operations.

Sep 1, 202510mo ago

Mirai variants begin exploiting TBK DVR flaw in the wild

Attackers began exploiting CVE-2024-3721 to infect vulnerable TBK DVR devices, with reports indicating the activity had been ongoing for months. Kaspersky also observed a separate Mirai variant abusing the same flaw, with infections concentrated in countries including China, India, Egypt, Ukraine, Russia, Turkey, and Brazil.

Jan 1, 20242y ago

CVE-2024-3721 disclosed in TBK Vision DVR devices

A command injection vulnerability, tracked as CVE-2024-3721, was identified in TBK DVR-4104 and DVR-4216 devices, including some rebranded models such as CeNova, Night Owl, and QSee. The flaw created an avenue for remote compromise of internet-exposed DVR systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Organizations
8 linked
CydomeKasperskyTBK VisionNight OwlQSeeCeNovaTBKSideWinder
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.