PULSE NAME
Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign
WHITE Nexus Team AlienVault 2026-04-17 Modified: 2026-04-20
21
IOCs
MEDIUM VOLUME
Nexcorium is a multi-architecture Mirai variant exploiting CVE-2024-3721 in TBK DVR devices to build a botnet for distributed denial-of-service attacks. The campaign, attributed to Nexus Team based on custom HTTP headers, uses OS command injection to deliver malware across ARM, MIPS, and x86-64 architectures. The malware implements multiple persistence mechanisms including init configuration, startup scripts, systemd services, and cron jobs. It features XOR-encoded configurations, self-integrity checks, and self-replication capabilities. Attack capabilities include UDP flood, TCP SYN flood, TCP ACK flood, and VSE query flood among others. The botnet spreads through brute-force attacks using default credentials and exploits CVE-2017-17215 targeting Huawei HG532 devices, demonstrating typical IoT-focused botnet characteristics.
Indicators of Compromise (2 / 21 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 353874dd1e12a7f67ba4f7ecbcbcb2af 2026-04-17
FileHash-MD5 aaed4dca8bd6bb42fc4efb358a02a554 2026-04-17