Also known as: tracked as, APT-C-41, Promethium, TargetCompany, FARGO
The Nexus Team—also known as APT‑C‑41, Promethium, TargetCompany, and FARGO—is believed to operate with a motivation of disruption rather than theft or espionage. Its most recent campaign revolves around the Mirai‑variant botnet "Nexcorium," which was first identified exploiting the CVE-2024‑3721 buffer overflow in TBK brand DVR devices. The initial compromise is achieved via an OS command injection that triggers execution of a lightweight downloader script (named 'dvr') distributed over HTTP with a signature X-Hacked-By header indicating "Nexus Team – Exploited By Erratic." Once installed, Nexcorium propagates across ARM, MIPS, and x86‑64 architectures by scanning the local network for default or weak credentials on Telnet and optionally exploiting CVE‑2017‑17215 against Huawei HG532 routers. The malware then employs a suite of persistence mechanisms—copying itself to "/usr/local/bin/sysd", creating init scripts, systemd services, and cron jobs—to maintain long‑term footholds even after reboot or partial cleanup. It validates its integrity via embedded hash checks and duplicates any tampered binaries to ensure resilience. Command and control communication is conducted over HTTPS, with the C2 domain r3brqw3d.b0ats.top used for receiving attack vectors. Nexcorium launches multiple DDoS modalities (UDP flood, TCP SYN, TCP ACK, VSE query flooding, etc.) dictated by attacker commands, thereby enabling the Nexus Team to generate disruptive network‑level traffic against a wide array of victim targets. The combination of low‑cost IoT exploitation, rapid self‑propagation, and flexible command and control underscores the actor’s capacity for large‑scale, coordinated denial-of-service operations while maintaining low visibility through custom HTTP traffic identifiers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Nexus Team is an IoT-focused threat actor that has recently deployed a Mirai‑variant botnet called Nexcorium, leveraging the CVE-2024-3721 vulnerability in TBK DVR devices to gain footholds and install its payload. Once the malware is on a device it establishes persistence, performs brute‑force credential guessing against Telnet interfaces, and reports back to a command‑and‑control domain (r3brqw3d.b0ats.top) from which it orchestrates large‑scale DDoS attacks. The actor’s operations suggest an ongoing, high‑tempo campaign targeting both industrial control systems and consumer IoT devices across multiple regions.
Goals & Targeting
The Nexus Team’s strategic objectives appear focused on causing widespread service disruption via high‑volume DDoS attacks against a diverse portfolio of sectors—including information technology, telecommunications, energy, defense, mining, government, education, and pharmaceuticals—across the United States, China, Vietnam, Australia, and Kazakhstan. The actor prioritizes low‑value, high‑impact targets such as IoT gateways, industrial control systems, and consumer network devices that can be quickly compromised through default or weak credentials and publicly disclosed vulnerabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Nexus Team demonstrates a recurring, high‑tempo campaign pattern characterized by rapid exploitation of publicly documented IoT vulnerabilities, automated brute‑force credential cracking to compromise devices, and immediate deployment of a lightweight Mirai-based botnet. Victim profiles skew toward networked industrial or consumer control devices—such as DVRs, routers, and SCADA components—that lack proper firmware patching and have weak authentication controls. Operational tempo is high; new vulnerabilities are leveraged quickly (e.g., CVE-2024‑3721 within days of disclosure), and the botnet can be re‑commissioned in minutes through automated download scripts. Notable past operations include widespread DDoS attacks on telecom infrastructure and energy utilities, with attackers leveraging custom HTTP headers for attribution and persistence mechanisms to survive defensive cleanup attempts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a coherent picture of the Nexus Team’s tactics, techniques, and procedures, largely derived from observed malware samples, public vulnerability disclosures, and network traffic signatures. Confidence in attribution is moderate—relying on custom HTTP headers and naming conventions within the downloader script—and operational detail remains limited to a few documented campaigns. Gaps persist regarding the actor's full organizational structure, long‑term strategic goals, detailed command‑and‑control infrastructure beyond the primary C2 domain, and historical engagement with other vulnerability families.
No campaigns linked yet.
No observed data linked yet.
15
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
9
Tactics