Broadside is a Mirai-derived botnet variant targeting the maritime logistics sector by exploiting CVE-2024-3721 in TBK DVR digital video recording devices deployed on seagoing vessels. It is associated with attacks against exposed onboard surveillance and recording infrastructure, using remote command injection to compromise devices and fold them into botnet operations. The malware departs from more conventional Mirai tradecraft through stealthier persistence and process control. Reported behavior includes Netlink-based process monitoring for persistence, dynamic termination and blacklisting of competing processes, attempts to harvest system credential material, and activity consistent with privilege escalation and lateral movement from compromised devices. Broadside also uses custom command-and-control communications and high-rate UDP flooding, with payload polymorphism and other defense-evasion measures intended to reduce static detection. Operationally, Broadside poses particular risk to maritime environments because vessel networks often contain legacy and poorly monitored systems, limited onboard security staffing, and constrained satellite connectivity. Botnet activity on infected marine assets can therefore degrade vessel operations and consume expensive bandwidth. Broadside is best understood as an IoT-focused botnet threat actor or operation centered on maritime targeting rather than a clearly attributed nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Broadside is a new Mirai botnet variant active in the wild, likely used for large-scale DDoS attacks.
Broadside is a Mirai botnet variant targeting the maritime logistics sector by exploiting a critical vulnerability (CVE-2024-3721) in TBK DVR-4104 and DVR-4216 devices. It uses command injection to hijack devices, achieve persistence, move laterally, and conduct high-rate UDP flooding attacks. The campaign is active and leverages advanced techniques for stealth and evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.