{"id":12244,"date":"2026-04-20T10:03:44","date_gmt":"2026-04-20T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/20\/hackers-use-cve-2024-3721-to-infect-tbk-dvrs-with-nexcorium-ddos-malware\/"},"modified":"2026-04-20T10:03:44","modified_gmt":"2026-04-20T10:03:44","slug":"hackers-use-cve-2024-3721-to-infect-tbk-dvrs-with-nexcorium-ddos-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/20\/hackers-use-cve-2024-3721-to-infect-tbk-dvrs-with-nexcorium-ddos-malware\/","title":{"rendered":"Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware"},"content":{"rendered":"<p>    Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch large-scale distributed denial-of-service attacks. <\/p>\n<p>The vulnerability at the center of this campaign, CVE-2024-3721, carries a CVSS score of 6.3 and affects TBK DVR-4104 and DVR-4216 device models, both of which have become prime targets due to their outdated firmware and consistently weak default credentials.<\/p>\n<p>The TBK DVR devices affected by this campaign have long been on the radar of security researchers due to their widespread deployment in small businesses, retail outlets, and surveillance setups where regular patching is rarely a priority. <\/p>\n<p>Once attackers find an exposed device, they send a specially crafted HTTP request to the vulnerable endpoint at\u00a0<code>\/device.rsp?opt=sys&amp;cmd=___S_O_S_T_R_E_A_MAX___<\/code>, injecting operating system commands without requiring any authentication. <\/p>\n<p>This single step gives the attacker remote code execution on the device, turning what was once a security camera recorder into an unwilling participant in a coordinated attack network.<\/p>\n<p><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" id=\"https:\/\/www.fortinet.com\/blog\/threat-research\/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fortinet\u2019s FortiGuard Labs researchers identified and analyzed this campaign<\/a> in detail, tracking the full infection chain from initial exploitation through payload delivery and persistence establishment. <\/p>\n<p>Their findings confirmed that Nexcorium shares a core architecture with the original Mirai botnet, including an XOR-encoded configuration table, a watchdog module that keeps the malware running, and a dedicated <a href=\"https:\/\/cybersecuritynews.com\/gcore-mitigates-record-breaking-6-tbps-ddos-attack\/\" id=\"129962\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS attack<\/a> module ready to flood targets on command. <\/p>\n<p>Fortinet noted that the malware displays the message \u201cnexuscorp has taken control\u201d upon execution, a deliberate signature that the threat actors embedded to announce their presence on the infected device.<\/p>\n<p>The campaign does not stop at TBK DVRs alone. Researchers also observed Nexcorium targeting end-of-life TP-Link Wi-Fi routers, exploiting CVE-2017-17215 to widen the pool of infected devices. <\/p>\n<p>This dual-target approach reveals a well-planned strategy to build a broad, mixed botnet by attacking hardware that organizations and home users are unlikely to patch or replace anytime soon. <\/p>\n<p>The combined reach of both device types creates a large, geographically distributed attack infrastructure that can be directed toward DDoS campaigns at scale.<\/p>\n<p>The impact of this malware goes beyond just the individual devices it infects. Every compromised DVR or router becomes an amplifier in a network capable of generating massive traffic floods against online services, businesses, and critical infrastructure. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhzsg1NOCK1RutHpS2ItwJ_uYaUhFlhSk-kvO2fER7fztUhNAwgyYm9LjtbXd2XyhWfp74Zy0H7bHqWkHkM14MTVfgAz910JHDTn3GyRnulkYOWDCb3rgPBY6hU_sEfFkplTJ1Uz3UWeiUmXOh5wZVrTHY5y78vA7YjfGxBPbZrD5xqMSGHKeUheDm259A\/s16000\/Downloader%2520shell%2520script%2520%27dvr%27%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"Downloader shell script 'dvr' (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">Downloader shell script \u2018dvr\u2019 (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>Since these devices run continuously and sit behind real IP addresses, the resulting <a href=\"https:\/\/cybersecuritynews.com\/new-botnet-leverages-dns-misconfiguration\/\" id=\"127351\" target=\"_blank\" rel=\"noreferrer noopener\">botnet traffic<\/a> appears legitimate to many filtering systems, making Nexcorium-driven attacks harder to block effectively.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-nexcorium-hooks-itself-in-and-avoids-removal\"><strong>How Nexcorium Hooks Itself In and Avoids Removal<\/strong><\/h2>\n<p>Once Nexcorium lands on a TBK DVR, its infection mechanism follows a structured sequence designed to ensure it stays active even if the device is rebooted or interfered with. <\/p>\n<p>The initial exploitation of CVE-2024-3721 retrieves a downloader script, which then identifies the underlying Linux system\u2019s processor architecture and pulls the correct compiled binary variant of the malware for that specific hardware. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiTUa4TpPZ4o0Bu-DvrWrpAStLQo-Y49NbaIwa2pQPVQqvE2BMGpmlDLRgcQWhevnCe2esRyLp56C5fPnCD8sBu9BJMAzIYqwbvAgOmqdPsCpQyhdR_gSmC-1s3FcgGGNpODDhyphenhyphenM9iB20g2EkpC9ZKeOFq4kiK9xUYryCj9llYd59KGqwJl0hLHPlb1qhQ\/s16000\/Watchdog%2520subprocess%2520role%2520marker%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"Watchdog subprocess role marker (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">Watchdog subprocess role marker (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>Nexcorium supports multiple CPU architectures, meaning it can infect a wide range of IoT hardware beyond the initial targets without needing to be rewritten.<\/p>\n<p>After deploying the correct binary, the malware embeds itself using multiple persistence methods to ensure it survives reboots and manual termination attempts. <\/p>\n<p>Fortinet\u2019s researchers observed that Nexcorium sets up a C2 communication channel through which the botnet operator can issue <a href=\"https:\/\/cybersecuritynews.com\/ddos-malware-cshell-exploit-linux-tools-to-attack-ssh-servers\/\" id=\"86555\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS commands<\/a>, monitor victim status, and push further instructions directly to infected nodes. <\/p>\n<p>The malware further strengthens its position by running a watchdog process that continuously monitors whether the main payload process is still active, automatically restarting it if something interrupts its execution.<\/p>\n<p>One of the more notable self-protection features Fortinet identified is that Nexcorium uses FNV-1a hashing algorithms to check its own binary integrity. <\/p>\n<p>If the file on disk has been altered or is no longer readable, perhaps due to a partial deletion or antivirus interference, the malware dynamically copies itself under a new filename to restore its own presence. <\/p>\n<p>On top of that, Nexcorium launches aggressive Telnet-based brute-force attacks against other devices on the same network and beyond, using a hardcoded list of common default credentials to self-propagate without any additional input from the attacker.<a href=\"https:\/\/cybersecuritynews.com\/nexcorium-associated-mirai-variant-uses-tbk-dvr-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Organizations and individuals running TBK DVR-4104 or DVR-4216 devices should replace them immediately with supported models, since the vendor has not released a patch for CVE-2024-3721 and these devices are considered end-of-life from a security standpoint. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh51Akt-SU5GXqOlkNpC3zNtLkdER1NrlBBjMS1mkp-mGa1sA1t4nNnp-QFTIAqr4CbmMASZJcPVgSeqvA2-_bFPO2_QH936jBsb5QnsLJK369_ZoG46rHfZk3Js1UVTj9QVu1gnKptb4gTsMdgmiqW8txH7MomDCwVQKcLP58Ia2XlIddji-qEbekN_40\/s16000\/Attack%2520method%2520to%2520parse%2520commands%2520from%2520the%2520C2%2520server%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"Attack method to parse commands from the C2 server (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">Attack method to parse commands from the C2 server (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>Similarly, any TP-Link routers running outdated firmware susceptible to CVE-2017-17215 should be retired and replaced. <\/p>\n<p>Administrators should also ensure that all internet-facing <a href=\"https:\/\/cybersecuritynews.com\/securing-iot-devices-3\/\" id=\"108816\" target=\"_blank\" rel=\"noreferrer noopener\">IoT devices<\/a> use strong, unique passwords rather than factory defaults, as Nexcorium\u2019s brute-force module specifically targets devices still running common credentials. <\/p>\n<p>Network segmentation is strongly advised, keeping DVRs and surveillance hardware isolated from critical internal systems to limit the damage if a device is compromised. <\/p>\n<p>Where possible, disabling remote access to DVR management interfaces that do not require external connectivity is one of the most effective ways to close the attack surface that this campaign relies upon.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-use-cve-2024-3721-to-infect-tbk-dvrs\/\">Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-use-cve-2024-3721-to-infect-tbk-dvrs\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch large-scale distributed denial-of-service attacks. The vulnerability at the center of this campaign, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12244","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12244"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12244"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12244\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}