Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Emergency improvement for AEM after releasing POCs after releasing emergency fix for AEM

    August 6, 2025

    Volume sheds 5% as a quadruple, tests major support areas

    August 6, 2025

    Openai returns to its open-source roots with the new open-weight AI model, and this is a big thing

    August 6, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New Mirai Botnet infected TBK DVR device through command injection flour
    Security

    New Mirai Botnet infected TBK DVR device through command injection flour

    PineapplesUpdateBy PineapplesUpdateJune 8, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Mirai Botnet infected TBK DVR device through command injection flour
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New Mirai Botnet infected TBK DVR device through command injection flour

    A new version of Mirai Malware Botnet is exploiting a command injection vulnerability in TBK DVR -4104 and DVR -4216 digital video recording devices to kidnap them.

    Defended, tracked under Cve-2024-3721A command injection is manifested by the security researcher “Natakfish“In April 2024.

    The proof-off-concept (POC) at that time came as a specially designed post request as a weak closing point, which receives shell command execution through manipulation of certain parameters (MDB and MDC).

    Kaspersky Now report The active exploitation of CVE-2024-3721 in its Linux Honeypots from a new Mirai Botnet variant was caught using Netsecfish’s POC.

    The attackers take advantage of exploitation to release an ARM32 malware binary, which establishes communication with the command and control (C2) server to list the device in a boteta flock. From there, the device is used to probably deny the distributed service (DDOS) attacks, proxy malicious traffic and other behavior.

    Mirai's Environment Czech
    Mirai’s Environment Czech
    Source: Kasperki

    Attack effect and improvement

    Although Netsecfish reported last year that around 114,000 internet-wishes were unsafe for DVR-2024-3721, Kaspersky’s scans show about 50,000 exposed equipment, which is still important.

    Most infections are associated with Russian Cyber ​​Security Firm the latest Mirai variant impact China, India, Egypt, Ukraine, Russia, Türkiye and Brazil. However, it is based on Kaspersky’s telemetry, and as it is banned on its consumer security products in many countries, it may not accurately reflect the targeting focus of the botnet.

    Currently, it is not clear whether the seller, TBK Vision has issued security updates to address the CVE -2024–3721 defects or if it remains unplaced. Bleepingcomputer contacted TBK to ask about this, but we are still waiting for their response.

    It is worth noting that DVR-4104 and DVR-4216 have been branded on a large scale under Novo, Cenova, QSEE, Pulnix, XVR 5 in 1, Securus, Night Owl, DVR Login, HVR Login, and MDVR brands, hence the availability of a complication for the affected devices.

    The researcher revealing the TBK Vision Flaw discovered other flaws, promoting exploitation against the end of life last year.

    In particular, Netsecfish has revealed a backdoor account issue and a command injection vulnerability in 2024, affecting thousands of EOL D-Link devices in 2024.

    A few days after the disclosure of POC, active exploitation was detected in both cases. This shows how soon the malware writers include public exploits in their arsenal.


    Tines needle

    Patching meant complex scripts, long and endless fire drills. No more.

    In this new guide, the tines break down how it is leveling with modern organ automation. Patch fast, reduce overhead, and focus on strategic tasks – no complex script is required.

    botnet command device DVR flour infected injection Mirai TBK
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleXbox Games Showcase 2025 Live: Person 4 remakes and all they are in the form of all major revelations
    Next Article Scientists discovered the heaviest proton-emergent nucleus after nearly 30 years.
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Emergency improvement for AEM after releasing POCs after releasing emergency fix for AEM

    August 6, 2025
    Security

    WIE Model Reference Protocol Gehackt Wird

    August 6, 2025
    Security

    How AI enhances these other technical trends that matters the most for trade in 2025

    August 6, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Emergency improvement for AEM after releasing POCs after releasing emergency fix for AEM

    August 6, 2025

    Volume sheds 5% as a quadruple, tests major support areas

    August 6, 2025

    Openai returns to its open-source roots with the new open-weight AI model, and this is a big thing

    August 6, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.