Fortinet and other reporting identified Nexcorium, a Mirai-derived malware strain targeting Internet of Things devices, particularly TBK DVR-4104 and DVR-4216 video recorder systems used with security cameras. The campaign exploits CVE-2024-3721, an OS command injection flaw, to run a downloader script that retrieves malware binaries for multiple Linux architectures. Fortinet linked the activity to a suspected actor it calls Nexus Team, citing the custom HTTP header X-Hacked-By: Nexus Team – Exploited By Erratic.
Once installed, Nexcorium uses classic Mirai-style scanner, watchdog, and attack modules, establishes persistence through mechanisms including init, rc.local, systemd, and cron, and spreads further through brute-force Telnet activity, default-password abuse, and exploitation of CVE-2017-17215 in Huawei HG532 devices. The malware performs self-checks, replication, and self-deletion to improve resilience and evasion, then connects to the command-and-control domain r3brqw3d[.]b0ats[.]top to receive instructions for DDoS operations, including UDP, TCP SYN, TCP ACK, SMTP, and VSE query floods.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Akamai documented a new Mirai-related botnet variant called 'tuxnokill' spreading via CVE-2025-29635 in D-Link DIR-823X routers. The campaign also probed TP-Link and ZTE devices through additional known vulnerabilities, showing parallel targeting of multiple IoT platforms.
Palo Alto Networks Unit 42 reported automated, but flawed, attempts to exploit CVE-2023-33538 in unsupported TP-Link Wi-Fi routers to deploy Mirai-like malware containing references to 'Condi.' The activity highlighted continued targeting of end-of-life IoT devices alongside the Nexcorium campaign.
Fortinet disclosed that its antivirus, web filtering, IPS, and anti-botnet services detect the malware, block its command-and-control infrastructure, and identify exploitation attempts against CVE-2024-3721. This marked the public defensive response accompanying disclosure of the campaign.
Analysis showed Nexcorium establishing persistence through init, rc.local, systemd, and cron, then connecting to the command-and-control domain r3brqw3d.b0ats.top. The malware was found to support multiple DDoS flood methods, including UDP, TCP SYN, TCP ACK, SMTP, and VSE query floods.
FortiGuard Labs linked the campaign to a suspected threat actor it calls 'Nexus Team,' citing the custom HTTP header 'X-Hacked-By: Nexus Team – Exploited By Erratic' seen in the activity. The attribution connected the Mirai-variant botnet operations to a named actor cluster.
The Nexcorium botnet was observed propagating beyond the initial DVR compromise by using brute-force Telnet attacks and exploiting CVE-2017-17215 in Huawei HG532 devices. This showed the campaign was designed to spread across multiple IoT device types and architectures.
A campaign began abusing CVE-2024-3721, an OS command injection flaw in TBK DVR-4104 and DVR-4216 devices, to execute a downloader script and install a multi-architecture Mirai variant later identified as Nexcorium. The malware targeted vulnerable IoT video recording devices as an initial foothold for botnet growth.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcefortinet.com
Open sourcefeeds.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.