Malware is an ARM binary, indicating that it is targeting devices, not your typical x86 Linux server. The compromised DVR likely happened via an exposed telnet port and a default root password (12345) The malware resides in /dev/cmd.so.so. A number of additional suspect files where located in the /dev directory which we still need to recover / analyze from the test system. The malware is just scanning for vulnerable devices, and the actual exploit will likely come later.”]