Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Emerging Nexcorium Botnet Exploits DVR Vulnerability

Emerging Nexcorium Botnet Exploits DVR Vulnerability

Posted on April 18, 2026 By CWS

A new variant of the infamous Mirai botnet, known as Nexcorium, has been identified, focusing on the exploitation of internet-connected video recording devices. This development is a significant concern in the cybersecurity community.

Exploitation of DVR Systems

Recent research from Fortinet’s FortiGuard Labs reveals that cybercriminals are utilizing a known vulnerability to compromise TBK DVR systems, forming a robust Distributed Denial-of-Service (DDoS) botnet. The specific devices targeted are TBK DVR-4104 and DVR-4216 models, which are vulnerable due to CVE-2024-3721, an operating system command injection flaw.

The attack involves manipulating device arguments to deploy a downloader script. The network traffic analysis shows a unique HTTP header, “X-Hacked-By: Nexus Team – Exploited By Erratic,” which has led researchers to attribute the attack to the so-called “Nexus Team” threat group.

Technical Aspects and Mechanisms

Fortinet’s investigation into Nexcorium’s structure highlights its similarities to traditional Mirai variants, particularly its use of XOR-encoded configurations and modular design. Key mechanisms include a modular architecture with a watchdog, scanning, and attack modules for DDoS operations.

The botnet expands its reach by incorporating an older vulnerability, CVE-2017-17215, targeting Huawei routers, and executing Telnet-based brute-force attacks using known default credentials. For self-preservation, Nexcorium employs FNV-1a hashing to verify its integrity, duplicating itself under a new name if tampered with.

Persistence and Attack Strategies

To ensure continued access to infected systems, Nexcorium uses multiple persistence strategies. It modifies system files like /etc/inittab and /etc/rc.local, creates a systemd service, and sets scheduled tasks via crontab.

Once established, the botnet deletes its original binary to avoid detection. Its primary goal is to execute powerful DDoS attacks, utilizing a wide range of methods such as UDP, TCP, SMTP floods, and more advanced techniques like VSE query floods.

Implications and Recommendations

The emergence of Nexcorium underscores the ongoing threat posed by outdated IoT devices. Cybersecurity experts recommend immediate patching of CVE-2024-3721, changing default credentials, and employing network segmentation to protect against these vulnerabilities.

Stay updated by following us on Google News, LinkedIn, and X for more cybersecurity insights. Reach out to us to share your stories.

Cyber Security News Tags:botnet operations, CVE-2024-3721, Cybersecurity, DDoS attack, DVR exploit, Fortinet, IoT security, Mirai variant, network vulnerability, Nexcorium

Post navigation

Previous Post: Tycoon 2FA Loses Ground Amid Rising Phishing Threats
Next Post: Apple Aims to Fix iPhone Bug Removing Czech Character

Related Posts

Threat Actors Exploiting DevOps Web Servers Misconfigurations To Deploy Malware Threat Actors Exploiting DevOps Web Servers Misconfigurations To Deploy Malware Cyber Security News
Supply Chain Attack Targets art-template npm Package Supply Chain Attack Targets art-template npm Package Cyber Security News
Vidar 2.0 Malware Targets Gamers via Fake Cheats Vidar 2.0 Malware Targets Gamers via Fake Cheats Cyber Security News
PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files Cyber Security News
ScreenConnect Abused by Threat Actors to Gain Unauthorized Remote Access to Your Computer ScreenConnect Abused by Threat Actors to Gain Unauthorized Remote Access to Your Computer Cyber Security News
Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails Google Gemini for Workspace Vulnerability Lets Attackers Hide Malicious Scripts in Emails Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark