#MiraiBotnet
FortiGuard Labs identified Nexcorium Mirai variant exploiting CVE-2024-3721 in TBK DVR-4104/4216 devices, using brute-force, persistence, and DDoS modules. Linked to Nexus Team actor via custom headers and infrastructure. #MiraiBotnet #IoTAttack
Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign
FortiGuard Labs analyzed a campaign exploiting CVE-2024-3721 in TBK DVR-4104 and DVR-4216 devices to install the multi-architecture Mirai variant Nexcorium, which uses downloader scripts, persistence tricks, brute-force login attempts, and DDoS modules. The activity is likely linked to the suspected “Nexus Team” threat actor, identified by a custom X-Hacked-By header and infrastructure including r3brqw3d[.]b0ats[.]top. #CVE-2024-3721 #Nexcorium #NexusTeam #TBKDVR-4104 #TBKDVR-4216 #r3brqw3d.b0ats.top
www.hendryadrian.com
May 9, 2026 at 10:00 AM
A critical pre-authentication bypass, CVE-2026-41940, targeting cPanel/WHM has triggered a surge in malicious hosts. Active campaigns involve Mirai variants and ransomware appending “.sorry” to files. #cPanelFlaw #RansomwareAttack #MiraiBotnet
The cPanel Situation Is… - Censys
A critical pre-authentication bypass, CVE-2026-41940, was disclosed in cPanel/WHM and coincided with a sharp spike in hosts classified as malicious. Analysis indicates two active campaigns—post-compromise Mirai deployments and a large-scale file-encrypting campaign appending “.sorry” to files—heavily targeting cPanel systems. #CVE-2026-41940 #cPanel
www.hendryadrian.com
May 5, 2026 at 12:30 PM
A new Mirai campaign exploits CVE-2025-29635 in EoL D-Link DIR-823X routers, using POST to /goform/set_prohibiting for RCE and deploying the multi-arch variant "tuxnokill." Detected globally in March 2026. #DLink #MiraiBotnet #USA
New Mirai campaign exploits RCE flaw in EoL D-Link routers
A Mirai-based botnet campaign is actively exploiting CVE-2025-29635 in D-Link DIR-823X routers to execute commands via a POST to /goform/set_prohibiting and enlist devices. Akamai SIRT observed the activity in March 2026 and found attackers download and run a multi-architecture Mirai variant called "tuxnokill," while affected models reached end-of-life in November 2024, making vendor fixes unlikely. #CVE-2025-29635 #tuxnokill
www.hendryadrian.com
April 23, 2026 at 12:00 AM
New Mirai variant 'Nexcorium' exploits IoT vulnerabilities to launch DDoS attacks. Ensure your devices are updated and secured. #CyberSecurity #IoT #DDoS #MiraiBotnet Link: thedailytechfeed.com/nexcorium-bo...
April 19, 2026 at 5:09 PM
New Mirai variant 'Nexcorium' exploits TBK DVR vulnerabilities to build a massive DDoS botnet. Stay vigilant! #CyberSecurity #IoT #MiraiBotnet #DDoS #TBKDVR #Nexcorium Link: thedailytechfeed.com/nexcorium-ne...
April 19, 2026 at 5:08 PM
🚨 Juniper alerts us about the Mirai botnet targeting SSR devices using default passwords! Don't let your devices be the next victim. 🔒 Read more: https://innovirtuoso.com/cybersecurity/juniper-warns-of-mirai-botnet-targeting-ssr-devices-with-default-passwords/ #Cybersecurity #MiraiBotnet #IoT
Juniper Warns of Mirai Botnet Targeting SSR Devices
Juniper Networks has issued an important alert about the Mirai botnet and its threats to Systematic Security Reporting (SSR) devices.
innovirtuoso.com
April 18, 2026 at 7:21 PM
🚨 Juniper alerts us about the Mirai botnet targeting SSR devices using default passwords! Don't let your devices be the next victim. 🔒 Read more: https://innovirtuoso.com/cybersecurity/juniper-warns-of-mirai-botnet-targeting-ssr-devices-with-default-passwords/ #Cybersecurity #MiraiBotnet #IoT
Juniper Warns of Mirai Botnet Targeting SSR Devices
Juniper Networks has issued an important alert about the Mirai botnet and its threats to Systematic Security Reporting (SSR) devices.
innovirtuoso.com
February 24, 2026 at 12:50 PM
A #Minecraft feud took down the internet. 🎮🌐 We expose the #MiraiBotnet: how 3 students weaponized toasters & cameras to attack #Dyn. Why did the #FBI hire the hackers who broke the web? #TechTakedown.

🎧 LISTEN NOW 👇
open.spotify.com/episode/18Ay...
The Minecraft Feud That Broke the Internet: The Mirai Botnet 🧠 Tech Takedown
open.spotify.com
December 2, 2025 at 12:27 PM
ShadowV2 is the latest IoT botnet targeting routers, cameras, and smart devices. A fast-spreading threat demanding stronger cybersecurity defenses.
👉 Contact us today!
📞 (949) 379-8499 | 🌐 technijian.com
#ShadowV2 #CyberSecurity #IoTSecurity #CyberThreats #MiraiBotnet #DDoS #InfoSec #TechNews
November 27, 2025 at 10:56 AM
Mirai Botnet Variant is Building Swarm by Exploiting DVR Flaw #CommandInjection #Linux #Miraibotnet
Mirai Botnet Variant is Building Swarm by Exploiting DVR Flaw
 A command injection flaw in internet-connected digital video recorders used for CCTV monitoring is the target of a Mirai botnet malware variant, which allows hackers to take over the devices and add them to a botnet.  Cybersecurity researchers at Russian cybersecurity firm Kaspersky discovered a CVE-2024-3721 exploit while analysing logs from their Linux honeypot system. The issue is a command injection vulnerability found in internet-connected digital video recorders used for CCTV surveillance. Further analysis revealed that the activity was related to a form of the Mirai botnet, which exploited this issue in TBK-manufactured DVR devices to compromise and control them.  The vulnerability was initially discovered by security researcher "netsecfish" in April 2024. By adjusting parameters like mdb and mdc, the researcher released a proof-of-concept showing how a carefully designed post request to a specific URL can trigger shell command execution. Kaspersky confirmed that this precise technique is being utilised in the wild, with its Linux honeypots catching ongoing exploitation attempts linked to a Mirai botnet variant that uses netsecfish's proof-of-concept to compromise vulnerable DVRs.  Nearly a decade ago, an anonymous source made the Mirai source code available online. It continues to act as the foundation for other evolving botnet efforts. The variant aimed at DVR systems expands on Mirai's initial foundation with extra features such as RC4-based string obfuscation, checks to avoid virtual machine environments, and anti-emulation methods.  The exploit is used by the attackers to transmit a malicious ARM32 program to the target device, which then connects to a command-and-control server and joins the botnet. The infected device can be used to launch distributed denial-of-service attacks, forward malicious traffic, and engage in other malicious actions. This Mirai variation uses a basic RC4 technique to decode its internal strings, with the decryption key disguised using XOR. After decryption, the strings are saved in a global list and used throughout runtime. To evade analysis, the virus runs anti-virtualization and anti-emulation checks on active processes for indicators of environments such as VMware or QEMU. Last year, Netsecfish reported that around 114,000 DVR devices were vulnerable to CVE-2024-3721. Kaspersky estimates the figure to be closer to 50,000. The majority of infections associated with this Mirai variation are found in Brazil, Russia, Egypt, China, India, and Ukraine.
dlvr.it
June 15, 2025 at 4:23 PM
🔒 Mirai Botnet waarschuwt! Hackers kunnen je DVR overnemen. Update je firmware en verander je wachtwoorden NU! #CyberSecurity #MiraiBotnet 🚨 - lees het hele verhaal op itinsights
June 9, 2025 at 5:30 PM
🚨Mirai Malware Targets Unpatched TBK DVRs in Global Botnet Campaign🚨 Contact for Security support@wiretor.com

Read: wiretor.com/mirai-botnet...

#MiraiBotnet, #CVE20243721, #IoTSecurity, #CyberSecurity, #DVRExploit, #BotnetAttack, #WireTor, #PenetrationTesting, #ThreatDetection, #InfoSec
Mirai Botnet Exploits TBK DVR Vulnerability (CVE-2024-3721)
A new Mirai botnet variant exploits CVE-2024-3721 to hijack TBK DVR devices via command injection, risking massive IoT attacks. Stay protected
wiretor.com
June 9, 2025 at 7:33 AM
Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit reconbee.com/samsung-patc...

#samsung #miraibotnet #MagicINFO9 #cve #botnet #cyberattack
Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit
released a proof-of-concept (PoC) read more about Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit
reconbee.com
May 15, 2025 at 9:44 AM
Urgent: Samsung MagicINFO 9 Server vulnerability (CVE-2024-7399) allows Mirai botnet deployment; update immediately! #Samsung #MiraiBotnet #Cybersecurity
Samsung MagicINFO Exploited To Deploy Mirai Botnet
Urgent: Samsung MagicINFO 9 Server vulnerability (CVE-2024-7399) allows Mirai botnet deployment; update immediately! #Samsung #MiraiBotnet #Cybersecurity
thehackernews.com
May 7, 2025 at 2:34 PM
Major surge in TVT DVR exploits linked to Mirai botnet. #MiraiBotnet #IoTsecurity #Cybersecurity
Surge in Exploitation Against TVT DVRs, Mirai Likely
Major surge in TVT DVR exploits linked to Mirai botnet. #MiraiBotnet #IoTsecurity #Cybersecurity
securityonline.info
April 9, 2025 at 10:54 PM
Mass Campaign of Murdoc Botnet Mirai: A New Variant of Corona Mirai

https://cybersonar.org/go/yKsQBv
Posted at 17:05

#MiraiBotnet #MurdocBotnet #CyberSecurityThreats
February 28, 2025 at 10:53 AM
🚨 The Mirai botnet is BACK! Scanning for vulnerable routers & launching DDoS attacks. Protect your devices: change default passwords & use firewalls! 🔒 #CyberSecurity #MiraiBotnet 🌐 www.techradar.com/pro/security...
Juniper Networks warns Mirai botnet is back and targeting new devices
Mirai is scanning for poorly protected Session Smart routers
www.techradar.com
December 21, 2024 at 1:12 PM