Nexcorium Botnet - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd

General News

Summary

Cybersecurity researchers detail an active campaign deploying a Mirai-derived botnet called Nexcorium by exploiting vulnerabilities in TBK DVRs (CVE-2024-3721) and legacy TP-Link routers. Attackers use a downloader that detects device architecture, installs appropriate payloads, and establishes persistence via crontab and systemd while connecting to remote command-and-control servers. The malware spreads by reusing known exploits, brute-forcing Telnet credentials, and exploiting other flaws such as CVE-2017-17215 on Huawei devices, then enabling multi-protocol DDoS capabilities (UDP, TCP, SMTP). The report highlights how outdated firmware, default credentials, and widely deployed IoT devices continue to fuel large-scale botnet operations and calls for stronger device security practices.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M