Nexus Team is a relatively unknown threat actor associated with a Mirai-related botnet campaign using the Nexcorium malware to compromise internet-exposed IoT devices. The activity has been linked to exploitation of CVE-2024-3721 in TBK DVR systems, particularly DVR-4104 and DVR-4216 devices, and the malware also contains propagation support for CVE-2017-17215 affecting Huawei HG532 devices. The campaign has additionally targeted outdated TP-Link routers, indicating a focus on poorly secured and end-of-life embedded Linux platforms. Nexcorium is a multi-architecture Linux botnet payload with Mirai-style watchdog, scanner, and attacker modules. It uses XOR-decoded embedded configuration data, connects to command-and-control infrastructure for tasking, and is designed primarily for botnet expansion and distributed denial-of-service operations. Supported attack methods include multiple UDP- and TCP-based flood techniques as well as application-layer flooding methods. The malware also includes Telnet brute-force propagation using hard-coded default credential lists, architecture discovery on compromised hosts, and automated payload deployment. The actor demonstrates capabilities beyond basic opportunistic exploitation. Nexcorium establishes persistence through multiple mechanisms, including init configuration changes, startup script modification, systemd service creation, and cron-based execution. It performs self-integrity checks, can replicate itself if tampering is detected, copies itself into system directories for persistence, and deletes its original binary after installation to hinder analysis and improve resilience. Attribution to Nexus Team is based on a custom HTTP header embedded in exploit traffic, and the group is not widely established in public reporting. The observed operations are consistent with financially unaligned botnet activity focused on building and maintaining DDoS-capable infrastructure from vulnerable IoT devices.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a botnet campaign targeting IoT devices, particularly TBK digital video recorders, deploying the Nexcorium malware for persistence and DDoS activity.
Possibly linked to a campaign exploiting TBK DVR devices and outdated TP-Link routers to deploy the Nexcorium Mirai variant for botnet growth and DDoS attacks.
Operating the Nexcorium Mirai-derived botnet to compromise internet-connected DVR devices and build a large-scale DDoS botnet.
Associated with a campaign exploiting CVE-2024-3721 in TBK DVR devices to deliver the Nexcorium Mirai variant, establish persistence, brute-force Telnet services, and conduct DDoS attacks via centralized C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.