← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign
Nexcorium is a multi-architecture Mirai variant exploiting CVE-2024-3721 in TBK DVR devices to build a botnet for distributed denial-of-service attacks. The campaign, attributed to Nexus Team based on custom HTTP headers, uses OS command injection to deliver malware across ARM, MIPS, and x86-64 architectures. The malware implements multiple persistence mechanisms including init configuration, startup scripts, systemd services, and cron jobs. It features XOR-encoded configurations, self-integrity checks, and self-replication capabilities. Attack capabilities include UDP flood, TCP SYN flood, TCP ACK flood, and VSE query flood among others. The botnet spreads through brute-force attacks using default credentials and exploits CVE-2017-17215 targeting Huawei HG532 devices, demonstrating typical IoT-focused botnet characteristics.
MITRE ATT&CK & Malware Families
Indicators of Compromise (2 / 21 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 353874dd1e12a7f67ba4f7ecbcbcb2af | — | 2026-04-17 | |
| FileHash-MD5 | aaed4dca8bd6bb42fc4efb358a02a554 | — | 2026-04-17 |