Cybersecurity researchers at Fortinet’s FortiGuard Labs have found a new malware that is taking over smart devices across the globe. This threat, named Nexcorium, is a new version of the infamous Mirai malware. It is built to create a botnet, which is a large network of infected IoT devices and gadgets controlled by hackers to carry out large-scale DDoS attacks. How the hackers gain access FortiGuard Lab’s security analysts have found that in this campaign, the key targets of hackers are video recording boxes used for security cameras, preferably the TBK DVR-4104 and DVR-4216 models. That’s probably because these devices are rarely updated and have weak security settings, hence being easier to compromise. According to researchers, attackers are abusing CVE-2024-3721, a command injection vulnerability in these specific devices, allowing hackers to gain access and run malicious code and gain persistent remote access. Upon successful compromise, it leads to the showing of a message on the system saying “NexusCorp has taken control.” This gives away the attackers’ identity, which, according to researchers, is the Nexus Team. They even leave a signature in the code that says “Nexus Team – Exploited By Erratic,” thus validating this attribution. Malware Capabilities In their blog post shared with Hackread.com ahead of publishing on Friday, Vincent Li of FortiGuard Labs noted that Nexcorium is a “multi-architecture” malware, which means it can work on different processors. The malware is also difficult to get rid of because it copies itself into several different folders. It then sets up automatic tasks so that if the device is turned off and on again, the malware just starts back up, and even deletes its own original files to hide from anyone trying to find it. To extend the botnet network, the malware tries to compromise other smart devices in the same
New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks
Read the original article
hackread.com →