216.73.217.22

Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721

· Published 06/06/2025 12:45 · Modified 08/06/2025 17:09

Export JSON

Essential information

Published
06/06/2025 12:45
Modified
08/06/2025 17:09
Tags
2025-06-06 CVE-2024-3721 anti-emulation anti-vm botnet ddos dvr iot mirai rc4 encryption
Related entities
17 observables, 1 intrusion sets (apt), 5 techniques (mitre), 1 malware, 6 others

Description

A new wave of attacks is exploiting to target TBK devices. The campaign uses a POST request to execute system commands without authorization, downloading and running an ARM32 binary. This variant includes features like RC4 string encryption, checks, and techniques. The malware verifies if it's running in a virtual environment and checks for allowed directories. Infected devices are primarily located in China, India, Egypt, Ukraine, Russia, Turkey, and Brazil. Over 50,000 exposed devices are potentially vulnerable. The 's main goal is to conduct attacks. Updating vulnerable devices and performing factory resets are recommended as protective measures.

External references