{"id":12221,"date":"2026-04-18T10:03:41","date_gmt":"2026-04-18T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit-to-scale-botnet-operations\/"},"modified":"2026-04-18T10:03:41","modified_gmt":"2026-04-18T10:03:41","slug":"nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit-to-scale-botnet-operations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit-to-scale-botnet-operations\/","title":{"rendered":"Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations"},"content":{"rendered":"<p>    Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. <\/p>\n<p>According to recent threat research published by Fortinet\u2019s FortiGuard Labs, threat actors are exploiting a known <a href=\"https:\/\/cybersecuritynews.com\/react-native-command-injection-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">command injection vulnerability<\/a> to hijack TBK DVR systems and construct a large-scale Distributed Denial-of-Service (DDoS) botnet.<\/p>\n<p>Fortinet researchers report that the campaign specifically targets TBK DVR-4104 and DVR-4216 models by exploiting CVE-2024-3721. This OS command injection flaw allows attackers to deliver a downloader script by manipulating arguments within the device system. <\/p>\n<p>During the exploitation phase, network traffic reveals a custom HTTP header reading \u201cX-Hacked-By: Nexus Team \u2013 Exploited By Erratic,\u201d leading FortiGuard Labs to attribute the campaign to a relatively unknown threat actor identified as the \u201c<a href=\"https:\/\/cybersecuritynews.com\/china-nexus-hackers-attacking-telecommunication\/\" target=\"_blank\" rel=\"noreferrer noopener\">Nexus Team<\/a>\u201c.<\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/04\/image-67.png?ssl=1\" alt=\"\u00a0Exploit traffic via CVE-2024-3721 (Source: Fortinet)\" class=\"wp-image-183817\"><figcaption class=\"wp-element-caption\">\u00a0Exploit traffic via CVE-2024-3721 (Source: Fortinet)<\/figcaption><\/figure>\n<p>Once the downloader script executes, it fetches multi-architecture payloads supporting ARM, MIPS, and x86-64 environments, subsequently displaying a console message stating \u201cnexuscorp has taken control\u201d.<\/p>\n<h2 class=\"wp-block-heading\" id=\"technical-capabilities-and-infection-mechanisms\"><strong>Technical Capabilities and Infection Mechanisms<\/strong><\/h2>\n<p>Fortinet\u2019s analysis reveals that Nexcorium shares <a href=\"https:\/\/cybersecuritynews.com\/mirai-based-botnets-evolve-into-massive-ddos\/\" target=\"_blank\" rel=\"noreferrer noopener\">fundamental architecture with traditional Mirai variants<\/a>, utilizing XOR-encoded configurations and modular components. The technical operation relies on several core mechanisms:<a href=\"https:\/\/thehackernews.com\/2026\/04\/mirai-variant-nexcorium-exploits-cve.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Modular Architecture:<\/strong>\u00a0The malware deploys standard Mirai features, including a watchdog module to distinguish sub-processes, a scanner for network propagation, and an attacker module for DDoS execution.<\/li>\n<li>\n<strong>Legacy Exploit Integration:<\/strong>\u00a0To maximize its infection radius, Nexcorium incorporates the older CVE-2017-17215 vulnerability, which targets Huawei router devices.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>\n<strong>Aggressive Brute-Forcing:<\/strong>\u00a0The malware launches Telnet-based brute-force attacks against other networked hardware using a hardcoded list of common and default credentials.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>\n<strong>Self-Preservation:<\/strong>\u00a0Nexcorium verifies its own integrity using FNV-1a hashing algorithms; if the binary is altered or unreadable, it dynamically duplicates itself under a new filename to evade detection.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/04\/image-66.png?ssl=1\" alt=\"\u00a0XOR-Encoded CVE-2017-17215 exploit (Source: Fortinet)\" class=\"wp-image-183816\"><figcaption class=\"wp-element-caption\">\u00a0XOR-Encoded CVE-2017-17215 exploit (Source: Fortinet)<\/figcaption><\/figure>\n<p>To maintain long-term access to compromised systems, the <a href=\"https:\/\/cybersecuritynews.com\/ghostclaw-ai-assisted-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware establishes persistence<\/a> through four distinct mechanisms rather than relying on a single configuration file. The botnet secures its foothold by:<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<ul class=\"wp-block-list\">\n<li>Modifying\u00a0<code>\/etc\/inittab<\/code>\u00a0to ensure automatic process restarts if the malware is terminated.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>Updating\u00a0<code>\/etc\/rc.local<\/code>\u00a0to guarantee execution during the device\u2019s system startup sequence.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>Creating a dedicated systemd service named\u00a0<code>persist.service<\/code>\u00a0for persistent background operation.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>Planting scheduled tasks via crontab for reliable post-reboot execution.<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/04\/image-65.png?ssl=1\" alt=\"Parsing the architecture information response from the victim host (Source: Fortinet)\" class=\"wp-image-183815\"><figcaption class=\"wp-element-caption\">Parsing the architecture information response from the victim host (Source: Fortinet)<\/figcaption><\/figure>\n<p>Following this extensive setup, Fortinet notes that Nexcorium deletes its original binary from the execution path to thwart security analysts.<\/p>\n<p>The primary objective of the Nexus Team campaign is launching devastating DDoS attacks. <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Based on FortiGuard Labs\u2019 decryption of the malware\u2019s configuration table<\/a>, Nexcorium communicates with a centralized command-and-control (C2) server to receive attack directives. <\/p>\n<p>Instead of a narrow attack scope, the botnet is equipped with a versatile arsenal of flood techniques. These include standard UDP, TCP ACK, TCP SYN, SMTP, and TCP PSH floods, alongside specialized attack vectors like VSE query floods and UDP blast attacks.<\/p>\n<p>The discovery of Nexcorium highlights the continuous weaponization of legacy IoT devices. Security experts strongly advise organizations to immediately patch CVE-2024-3721, replace default manufacturer credentials, and isolate critical infrastructure from vulnerable IoT endpoints using network segmentation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit\/\">Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet\u2019s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability to hijack TBK DVR [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[660,129,63],"tags":[130],"class_list":["post-12221","post","type-post","status-publish","format-standard","hentry","category-botnet","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12221"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12221"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12221\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}