Malware, Vulnerability Management, IoT, Threat Intelligence

Broadside botnet exploits TBK DVR vulnerability, threatening maritime logistics

botnet bot-net computer virus

According to a report by Security Affairs, researchers have uncovered a new variant of the Mirai botnet, named Broadside, actively targeting the maritime logistics sector. This botnet exploits a critical command injection vulnerability, CVE-2024-3721, in TBK Vision DVR devices commonly found on vessels.

The Broadside botnet, a modification of the decade-old Mirai, employs a custom command and control protocol and unique modules for stealth and evasion. It utilizes Netlink kernel sockets and payload polymorphism to avoid detection. Beyond launching UDP-based distributed denial-of-service (DDoS) attacks, Broadside also steals sensitive credential files like /etc/passwd and /etc/shadow, facilitating privilege escalation and lateral movement within a compromised network. The vulnerability affects TBK DVRs and rebranded models from manufacturers such as CeNova, Night Owl, and QSee. Researchers have observed fluctuating activity from the botnet's infrastructure over several months.

The exploitation of these DVRs poses significant risks to shipping companies, potentially compromising CCTV feeds of critical areas like the bridge and engine rooms, disrupting satellite communications, or providing an entry point to operational technology (OT) systems. The secondary objective of credential harvesting highlights a shift from simple DDoS attacks to more sophisticated espionage and network infiltration, underscoring the need for enhanced cybersecurity measures and timely patching of vulnerable IoT devices in critical infrastructure sectors.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds