Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721

June 8, 2025, 5:09 p.m.

Description

A new wave of Mirai botnet attacks is exploiting CVE-2024-3721 to target TBK DVR devices. The campaign uses a POST request to execute system commands without authorization, downloading and running an ARM32 binary. This Mirai variant includes features like RC4 string encryption, anti-VM checks, and anti-emulation techniques. The malware verifies if it's running in a virtual environment and checks for allowed directories. Infected devices are primarily located in China, India, Egypt, Ukraine, Russia, Turkey, and Brazil. Over 50,000 exposed DVR devices are potentially vulnerable. The botnet's main goal is to conduct DDoS attacks. Updating vulnerable devices and performing factory resets are recommended as protective measures.

Date

  • Created: June 6, 2025, 12:45 p.m.
  • Published: June 6, 2025, 12:45 p.m.
  • Modified: June 8, 2025, 5:09 p.m.

Indicators

  • f3989e7cca7d17c909c5f53945c7846d2d269d32113042bf535285c4d75624e6
  • e5f9a505082501b32d442a3fa6a9fb40a48b7da91a5a0efc5677bed5401e0c2b
  • dd54e4a0220b6afbe0dbee66e32af3fe2012cc37023044a683e8e0c98579a059
  • dd2c66661d94f007d87754dcbc1ace9f228785676632a39fef2ce0e26d54e206
  • b2be07ed781bcdef614cd7c1461d81bfd8df2bc7eb11b6bfb5b202af881d727c
  • 9ae1955b9de5e4e6b23e55d2aab3230ff3a6b5c723d77a6653b2145719dc2eb6
  • 86ef39910b9361f012f889146e16b2e279a07465fe3e2f9b493ef0534a5c66c0
  • 7461c0f8feac69a39586c4c1ecfeb32627c5a83043721ba0144479efc0f036a1
  • 52bd9e57f7db2716d2ec570bc9a5de9ba96bc620edb3ac9469b5b131b004a030
  • 4abacef49032666c0d0b4a006368386bdc6c0367f6c5e21b022b650fb8dabdbc
  • 438dc2a85e37356eefd2d40ac7bafa8c3ad273dd36991d4b155208c3a3d460b5
  • 3bdbed482342487e08f5266e1a9b6478fcd0be645edcfb1e8c6dda1dac73cce9
  • 2a397594a3b009df342886a3480264a8773971559c79c8f95b1319eae77c55d6
  • 29754b61a1cce8c965bbc98efb125991b8b605dea9f3394c277092f30a109bdb
  • 1c39dbf66a362df572af7ad64164cc7d70a8875db68a710979d243760d8c027b
  • 63.231.92.27
  • 42.112.26.36

Attack Patterns

Additional Informations

  • Egypt
  • India
  • China
  • Ukraine
  • Brazil
  • Russian Federation