Nexus Team is a relatively unknown, provisionally identified IoT-botnet operator associated with a Mirai-derived malware family named Nexcorium. The attribution is based on a self-identifying custom HTTP request header observed during exploitation activity; the operators’ identity, origin, and broader affiliations remain unconfirmed. The campaign compromises vulnerable TBK digital video recorders through CVE-2024-3721, an OS command-injection vulnerability, and deploys payloads built for multiple Linux architectures. Nexcorium also propagates through Telnet brute forcing using common default credentials and incorporates exploitation of CVE-2017-17215 affecting Huawei HG532 devices. The malware uses scanner, watchdog, and attack components; establishes redundant persistence through init configuration, startup scripts, systemd services, and cron; performs integrity checks and self-replication; and deletes its initially executed binary to hinder analysis. Compromised devices receive commands from centralized infrastructure and can conduct distributed denial-of-service attacks using multiple UDP and TCP flood methods, as well as application-layer and query-flood techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A dark-web service claiming to provide searchable access to a large, allegedly continuously updated collection of North American identity documents, including driver’s licenses, ID cards, travel documents, medical cards, images, barcode data, and scans. Its claimed collection source and acquisition method remain unverified and are reportedly under FBI investigation.
Operated an illicit dark-web identity-data marketplace offering approximately 153 million driver's-license scans plus millions of other identity, travel, and medical-card records reportedly sourced from IDScan.net. The service shut down shortly after public reporting.
Operating a botnet campaign targeting IoT devices, particularly TBK digital video recorders, deploying the Nexcorium malware for persistence and DDoS activity.
Possibly linked to a campaign exploiting TBK DVR devices and outdated TP-Link routers to deploy the Nexcorium Mirai variant for botnet growth and DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.