Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureembedded-device-vulnerabilitycommand-and-control-methodpersistence-method

Nexcorium Mirai Variant Exploits TBK DVR Flaw to Build IoT DDoS Botnet

Updated 2mo agoFirst seen Apr 17, 20269 sources

Fortinet and other reporting identified Nexcorium, a Mirai-derived malware strain targeting Internet of Things devices, particularly TBK DVR-4104 and DVR-4216 video recorder systems used with security cameras. The campaign exploits CVE-2024-3721, an OS command injection flaw, to run a downloader script that retrieves malware binaries for multiple Linux architectures. Fortinet linked the activity to a suspected actor it calls Nexus Team, citing the custom HTTP header X-Hacked-By: Nexus Team – Exploited By Erratic.

Once installed, Nexcorium uses classic Mirai-style scanner, watchdog, and attack modules, establishes persistence through mechanisms including init, rc.local, systemd, and cron, and spreads further through brute-force Telnet activity, default-password abuse, and exploitation of CVE-2017-17215 in Huawei HG532 devices. The malware performs self-checks, replication, and self-deletion to improve resilience and evasion, then connects to the command-and-control domain r3brqw3d[.]b0ats[.]top to receive instructions for DDoS operations, including UDP, TCP SYN, TCP ACK, SMTP, and VSE query floods.

Share:
Nexcorium Mirai Variant Exploits TBK DVR Flaw to Build IoT DDoS Botnet
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 22, 20262mo ago

Akamai identifies tuxnokill botnet exploiting D-Link DIR-823X routers

Akamai documented a new Mirai-related botnet variant called 'tuxnokill' spreading via CVE-2025-29635 in D-Link DIR-823X routers. The campaign also probed TP-Link and ZTE devices through additional known vulnerabilities, showing parallel targeting of multiple IoT platforms.

New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Apr 18, 20262mo ago

Unit 42 spots Condi-linked exploitation attempts on TP-Link routers

Palo Alto Networks Unit 42 reported automated, but flawed, attempts to exploit CVE-2023-33538 in unsupported TP-Link Wi-Fi routers to deploy Mirai-like malware containing references to 'Condi.' The activity highlighted continued targeting of end-of-life IoT devices alongside the Nexcorium campaign.

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Apr 17, 20262mo ago

Fortinet publishes detections and blocking coverage for Nexcorium campaign

Fortinet disclosed that its antivirus, web filtering, IPS, and anti-botnet services detect the malware, block its command-and-control infrastructure, and identify exploitation attempts against CVE-2024-3721. This marked the public defensive response accompanying disclosure of the campaign.

Researchers identify Nexcorium C2 and DDoS botnet functionality

Analysis showed Nexcorium establishing persistence through init, rc.local, systemd, and cron, then connecting to the command-and-control domain r3brqw3d.b0ats.top. The malware was found to support multiple DDoS flood methods, including UDP, TCP SYN, TCP ACK, SMTP, and VSE query floods.

FortiGuard attributes Nexcorium activity to suspected 'Nexus Team'

FortiGuard Labs linked the campaign to a suspected threat actor it calls 'Nexus Team,' citing the custom HTTP header 'X-Hacked-By: Nexus Team – Exploited By Erratic' seen in the activity. The attribution connected the Mirai-variant botnet operations to a named actor cluster.

Nexcorium expands via Telnet brute force and Huawei HG532 exploitation

The Nexcorium botnet was observed propagating beyond the initial DVR compromise by using brute-force Telnet attacks and exploiting CVE-2017-17215 in Huawei HG532 devices. This showed the campaign was designed to spread across multiple IoT device types and architectures.

Attackers exploit CVE-2024-3721 in TBK DVR devices to deploy Nexcorium

A campaign began abusing CVE-2024-3721, an OS command injection flaw in TBK DVR-4104 and DVR-4216 devices, to execute a downloader script and install a multi-architecture Mirai variant later identified as Nexcorium. The malware targeted vulnerable IoT video recording devices as an initial foothold for botnet growth.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

33 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
FortigateFortimailFortiedrForticlient
Organizations
16 linked
FortinetHuawei TechnologiesTBKTP-LinkD-LinkAkamai TechnologiesZTE CorporationGitHubTBK VisionCloudSEKPalo Alto NetworksHackReadMotorolaSecurity AffairsGuruculHikvision Digital Technology
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.