Nexcorium Botnet - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd
Summary
Cybersecurity researchers detail an active campaign deploying a Mirai-derived botnet called Nexcorium by exploiting vulnerabilities in TBK DVRs (CVE-2024-3721) and legacy TP-Link routers. Attackers use a downloader that detects device architecture, installs appropriate payloads, and establishes persistence via crontab and systemd while connecting to remote command-and-control servers. The malware spreads by reusing known exploits, brute-forcing Telnet credentials, and exploiting other flaws such as CVE-2017-17215 on Huawei devices, then enabling multi-protocol DDoS capabilities (UDP, TCP, SMTP). The report highlights how outdated firmware, default credentials, and widely deployed IoT devices continue to fuel large-scale botnet operations and calls for stronger device security practices.