Thehackernews Nexcorium Malware Targets IoT Devices Using Mirai Variant for DDoS Attacks
Article Content
- •Nexcorium exploits CVE-2024-3721 in TBK DVR systems for DDoS botnet creation.
- •The malware targets specific models of video recording devices and outdated TP-Link routers.
- •Continuous adversarial testing is essential for organizations to mitigate risks from IoT vulnerabilities.
A new malware variant named Nexcorium has emerged, exploiting vulnerabilities in TBK DVR systems to create a botnet for large-scale DDoS attacks. This malware is a variant of the infamous Mirai botnet and primarily targets video recording devices, particularly the TBK DVR-4104 and DVR-4216 models, which have known security flaws. Attackers leverage CVE-2024-3721, a command injection vulnerability, to gain unauthorized access and execute malicious code. Nexcorium is capable of multi-architecture compatibility and employs robust persistence mechanisms, making it difficult to eradicate. The malware also utilizes brute-force techniques and a list of default passwords to compromise additional network-connected devices. Experts stress the importance of continuous adversarial testing to identify and mitigate risks associated with overlooked IoT devices. The threat is particularly significant given the increasing number of IoT devices that lack proper security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…