TVT DVRs become prime target for Mirai botnet

 TVT DVRs become prime target for Mirai botnet

Published on April 9, 2025 | Category: tech

TVT DVRs become prime target for Mirai botnet

News
By Sead Fadilpašić published

Mirai operators are actively scanning for vulnerable TVT DVRs

Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
(Image credit: Getty Images)

  • GreyNoise says scannings for vulnerable TVT DVRs are spiking
  • More than 2,500 unique IP addresses were hunting at one point
  • A 2024 vulnerability allows threat actors to run admin commands on the device

Operators of the Mirai botnet are actively hunting for vulnerable TVT DVRs to assimilate them into the nefarious network, cybersecurity researchers GreyNoise have revealed after observing a spike in exploitation attempts.

In May 2024, security researchers from SSD Secure Disclosure reported on a vulnerability affecting NVMS9000 DVRs built by the Shenzhen-based TVT Digital Technology manufacturer. The vulnerability was described as an authentication bypass, allowing threat actors to run admin commands on the device unabated.

All versions prior to 1.3.4 were said to be affected, but a patch was released and versions 1.3.4 and newer were no longer vulnerable.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

"No malicious files hosted"

Users who don’t keep track of updates and don’t patch their systems on time are now at risk. GreyNoise said that on April 3 the attack peaked, with more than 2,500 unique IP addresses scanning for vulnerable endpoints. We don’t know how many of these DVRs there are or how big the attack surface might be.

The researchers said that the malware being deployed on the DVRs is tied to Mirai, one of the most infamous botnets in cybersecurity history. Mirai usually targets smart devices, Internet of Things (IoT) devices, and internet-connected hardware, and is used to run disruptive Distributed Denial of Service (DDoS) attacks.

GreyNoise said that in the past 30 days it logged 6,600 unique IP addresses associated with this activity. All of the addresses were confirmed to be malicious. They mostly came from Taiwan, Japan, and South Korea, targeting devices in the US, UK, and Germany.

Mirai operators are quite active this year. In mid-January, news broke that they targeted industrial routers vulnerable to a zero-day. A few weeks later, security researchers from Akamai said they caught a new variant of the botnet targeting business phone devices built by Mitel.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Via BleepingComputer

You might also like

  • Watch out, your office phone could be hijacked into a Mirai botnet
  • We've rounded up the best password managers
  • Take a look at our guide to the best endpoint protection
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
A computer being guarded by cybersecurity.

CrushFTP vulnerability exploited in the wild, added to CISA KEV database

Google Chrome on macOS

Ancient flaw that allowed hackers to view your Chrome browser history has finally been patched, so update now

Latest
Dan Clark Audio Noire X headphones on black background, with TR's 'Money No Object' badge

Dan Clark Audio's Noire X are the Johnny Cash of elite planar magnetic headphones and I must have them

See more latest
Most Popular
Dan Clark Audio Noire X headphones on black background, with TR's 'Money No Object' badge
Dan Clark Audio's Noire X are the Johnny Cash of elite planar magnetic headphones and I must have them
A screenshot from the 1939 Wizard of Oz movie
The Wizard of Oz is coming to the Las Vegas sphere in 16K thanks to the power of Google DeepMind AI
An Nvidia GeForce RTX 4060 Ti
Nvidia RTX 5060 Ti price rumor is what all gamers want to hear – these models may be cheaper than RTX 4060 Ti equivalents, especially the 16GB GPU
Someone holding an iPhone showing the Spotify app logo
No, Spotify Premium won't be getting ads: subscribers can relax as Spotify debunks rumors
A battle between players with tanks in Civilization 7.
The next Civilization 7 update is finally bringing back something I think should've been in the game from the start
Two young women in casual wear slouch on a sofa. The sofa is in a residential street and is bookended by small chests of drawers with cushions, boxes and other junk on top.
Netflix's #2 most-watched movie is a new buddy comedy with 94% on Rotten Tomatoes – here are 3 more to watch next
Two Android phones on a green and blue background showing Google Messages
Google Messages has developed a very annoying emoji reaction bug, users report
Strava map rendering
Strava has added 4 new features users will love, including a massive map rendering overhaul
Person cooking 10 burgers using Ninja Sizzle Pro XL indoor grill
Ninja's new indoor grill lets you cook 10 burgers at once and doesn't need scrubbing afterward
Google Pixel Watch 3
Download Google's latest Pixel Watch update now to solve notification lag and crashing issues

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More