Back to Feed
IoT/OTApr 18, 2026

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

Nexcorium Mirai variant exploits CVE-2024-3721 in TBK DVRs to create DDoS botnet.

Vendor Watch

Run TP-Link?

Get an email when a reviewed story names TP-Link, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

A new Mirai variant called Nexcorium is exploiting CVE-2024-3721 in TBK DVRs to create a DDoS botnet. The botnet also exploits CVE-2017-17215 to target Huawei devices and uses brute-force attacks with hardcoded credentials. Researchers also detected flawed exploit attempts targeting EoL TP-Link routers using CVE-2023-33538.

Full text

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet Ravie LakshmananApr 18, 2026IoT Security / Vulnerability Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR devices has been found to exploit CVE-2024-3721 (CVSS score: 6.3), a medium-severity command injection vulnerability affecting TBK DVR-4104 and DVR-4216 digital video recording devices, to deliver a Mirai variant called Nexcorium. "IoT devices are increasingly prime targets for large-scale attacks due to their widespread use, lack of patching, and often weak security settings," security researcher Vincent Li said. "Threat actors continue exploiting known vulnerabilities to gain initial access and deploy malware that can persist, spread, and cause distributed denial-of-service (DDoS) attacks." This is not the first time the vulnerability has been exploited in the wild. Over the past year, the security issue has been leveraged to deploy a Mirai variant as well as a distinct, relatively new botnet called RondoDox. In September 2025, CloudSEK also disclosed details of a large-scale loader-as-a-service botnet that has been distributing RondoDox, Mirai, and Morte payloads through weak credentials and old flaws in routers, IoT devices, and enterprise apps. The attack activity outlined by Fortinet involves the exploitation of CVE-2024-3721 to obtain and drop a downloader script, which then launches the botnet payload based on the Linux system's architecture. Once the malware is executed, it displays a message stating "nexuscorp has taken control." "Nexcorium has a similar architecture to the Mirai variant, including XOR-encoded configuration table initialization, watchdog module, and DDoS attack module," the security vendor said. The malware also includes an exploit for CVE-2017-17215 to target Huawei HG532 devices in the network and incorporates a list of hard-coded usernames and passwords for use in brute-force attacks targeting the victim's hosts by opening a Telnet connection. If the Telnet login is successful, it attempts to obtain a shell, set up persistence using crontab and systemd service, and connect to an external server to await commands for launching DDoS attacks over UDP, TCP, and SMTP. Once persistence is established on the device, the malware deletes the original downloaded binary to evade analysis. "The Nexcorium malware displays typical traits of modern IoT-focused botnets, combining vulnerability exploitation, support for multiple architectures, and various persistence methods to sustain long-term access to infected systems," Fortinet said. "Its use of known exploits, such as CVE-2017-17215, along with extensive brute-force capabilities, underscores its adaptability and efficacy in increasing its infection reach." The development comes as Unit 42 said it detected active, automated scans and probes attempting to exploit CVE-2023-33538 (CVSS score: 8.8), a command injection vulnerability impacting EoL TP-Link wireless routers, albeit using a flawed approach that doesn't result in a successful compromise. It's worth noting that the security flaw was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog in June 2025. The vulnerability affects the following models - TL-WR940N v2 and v4 TL-WR740N v1 and v2 TL-WR841N v8 and v10 "Although the in-the-wild attacks we observed were flawed and would fail, our analysis confirms the underlying vulnerability is real," researchers Asher Davila, Malav Vyas, and Chris Navarrete said. "Successful exploitation requires authentication to the router's web interface." The attacks, in this case, attempt to deploy a Mirai-like botnet malware, with the source code featuring numerous references to the string "Condi." It also comes equipped with the ability to update itself with a newer version and act as a web server to spread the infection to other devices that connect to it. Given that the affected TP‑Link devices are no longer actively supported, users are advised to replace them with a newer model and ensure that default credentials are not used. "For the foreseeable future, the security landscape will continue to be shaped by the persistent risk of default credentials in IoT devices," Unit 42 said. "These credentials can turn a limited, authenticated vulnerability into a critical entry point for determined attackers." Update In a new analysis published on April 21, Akamai said it identified threat actors exploiting a command injection vulnerability impacting end-of-life D-Link DIR-823X series routers (CVE-2025-29635, CVSS score: 8.8) to deploy a Mirai botnet variant named "tuxnokill" via a shell script. The activity was detected against its honeypots in early March 2026. In addition to CVE-2025-29635, the attack has been observed attempting to exploit two other vulnerabilities: CVE-2023-1389, which affects TP-Link Archer AX21 devices, and a ZTE ZXV10 H108L router remote code execution (RCE) exploit. The campaigns are part of a broader effort undertaken by various threat actors to exploit known vulnerabilities in unpatched and retired IoT hardware, stealthily conscript them into a botnet, and then use those botnets to launch DDoS attacks. "Mirai malware campaigns continue to plague the industry, with much of the original source code continuing to be re-used by various threat actors, both skilled and unskilled," the company said. "The low barrier of entry and potential financial benefits are some of the incentives that may entice individuals to enter the botnet space and become a cyberthreat actor." (The story was updated after publication on April 22, 2026, to include details of additional Mirai botnet activity.) Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  botnet, CISA, Command Injection, cybersecurity, ddos, Fortinet, iot security, mirai, TP-LINK, Vulnerability ⚡ Top Stories This Week Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories Microsoft Warns of Two Actively Exploited Defender Vulnerabilities 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective The New Phishing Click: How OAuth Consent Bypasses MFA Developer Workstations Are Now Part of the Software Supply Chain ⭐ Featured Resources Claim ANY.RUN Anniversary Offer for Faster Malware Analysis [Guide] Learn to Detect AI Typosquatting Risks in Your Domain [Guide] Get Key Identity Security Insights From 2026 Snapshot Discover How to Navigate the Era of Constant Cyber Exposure

Indicators of Compromise

  • cve — CVE-2024-3721
  • cve — CVE-2017-17215
  • cve — CVE-2023-33538

Entities

Nexcorium (threat_actor)TBK DVR-4104 (product)TBK DVR-4216 (product)Huawei HG532 (product)TP-Link (vendor)