Broadside is a Mirai-derived botnet targeting Linux-based TBK Vision digital video recorders, including devices deployed aboard vessels in the maritime logistics sector. Identified by Cydome in December 2025, it exploits CVE-2024-3721, an unauthenticated remote OS command injection vulnerability, to execute a loader that retrieves and runs architecture-specific payloads. Its deployment chain uses in-memory execution and removes disk artifacts to reduce detection.
Broadside supports high-rate UDP flooding for distributed denial-of-service attacks and communicates through a custom TCP command-and-control protocol. It uses payload polymorphism to evade static defenses and Netlink kernel sockets for event-driven process monitoring. A process-control module dynamically terminates and blacklists competing or hostile processes, helping maintain exclusive control and persistence on infected devices. The malware also attempts to harvest local account and password-hash data; successful privilege escalation or lateral movement has not been established. On shipboard networks, its flooding capability can consume constrained satellite bandwidth and disrupt connectivity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This campaign was found to target the maritime logistics sector, exploiting a vulnerability (CVE-2024-3721) in TBK DVR (Digital Video Recorders) devices in use by shipping companies on vessels (among others).
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Broadside is a new variant of the Mirai botnet, active in the wild and likely used for DDoS attacks.
Mirai-based botnet variant that exploits a TBK DVR vulnerability, uses a custom C2 protocol and stealth techniques (e.g., Netlink kernel sockets, payload polymorphism), attempts to maintain exclusivity by killing competing processes, and harvests credential files (/etc/passwd, /etc/shadow) to establish foothold.
A new Mirai variant targeting TBK DVRs, especially in the maritime sector, to build an IoT botnet for malicious activities.
Broadside is a Mirai-based botnet variant that targets TBK DVR devices, primarily in the maritime logistics sector. It exploits CVE-2024-3721 to compromise devices, enabling DDoS attacks, credential theft, privilege escalation, and lateral movement. It features custom C2 protocols, payload polymorphism, and process-killing modules for persistence and stealth.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.