A backdoor in Xiongmai-based DVRs, NVRs, and IP cameras exposed affected devices to remote takeover by allowing attackers to recover a pre-shared key, authenticate over TCP/9530, and enable telnet access for root-level control. The issue affected products sold under many brands and hundreds of models, particularly devices built on HiSilicon-based hardware running Xiongmai firmware, with Internet-exposed vulnerable systems estimated in the hundreds of thousands to millions. Public reporting said the flaw stemmed from Xiongmai software rather than HiSilicon itself, and warned that patching across the fragmented OEM ecosystem was unreliable.
Researchers later linked active exploitation of the flaw to LeetHozer, a Mirai-like IoT botnet that targeted Xiongmai H.264/H.265 devices by abusing port 9530 to turn on telnet and then logging in with default credentials. Netlab 360 said the malware appeared related to the Moobot ecosystem through shared exploit strings and downloader infrastructure, while using redesigned bot logic, encryption, and C2 communications. Once installed, LeetHozer supported multiple DDoS functions, including tcpraw, icmpecho, and udpplain, showing how a widely deployed firmware backdoor moved quickly from public disclosure to operational botnet abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On the same day LeetHozer activity was first seen, researchers observed LeetHozer samples fetched from /ab/i686 and /ab/i586 and a moobot_xor sample fetched from /ab/arm from the same downloader infrastructure at 185.172.110.224. The overlap supported an assessment that the malware families were likely operated by the same actor or group.
Netlab 360 captured a suspicious malware sample later named LeetHozer. The sample marked the beginning of observed LeetHozer exploitation activity against Xiongmai H.264 and H.265 devices.
Researchers observed a moobot_xor variant exploiting the same TCP 9530 vulnerability in Xiongmai devices. This showed active weaponization of the issue shortly after the PoC became public.
A proof of concept for the Xiongmai device vulnerability exposed on TCP port 9530 was released on GitHub. The PoC demonstrated how attackers could trigger telnet on affected DVR, NVR, and IP camera devices.
A Chinese-language blog post documented how telnet could be enabled on Xiongmai cameras, showing public knowledge of the device access mechanism years before the 2020 GitHub PoC and later botnet exploitation. The post focused on research into Xiongmai camera telnet activation.
Hangzhou Xiongmai Technology published a security advisory addressing vulnerabilities affecting some XM products. The advisory predates the 2017 public blog documentation and later 2020 PoC and botnet exploitation activity already captured in the timeline.
Netlab 360 published technical analysis describing LeetHozer as a Mirai-like but distinct botnet family likely related to the Moobot group. The report documented its exploitation of Xiongmai devices via port 9530, default-credential logins, DDoS capabilities, and C2 infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceblog.netlab.360.com
Open sourcehabr.com
Open sourcecnblogs.com
Open sourcexiongmaitech.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.