high_confidence

Quad7 Activity

Quad7 Activity, also known as CovertNetwork-1658 or the 7777 Botnet, is a network of compromised small office/home office (SOHO) routers. (Citation: Bitsight 7777 Botnet) (Citation: Microsoft Storm-0940) The botnet was initially composed primarily of TP-Link routers and was named Quad7 due to compromised devices exposing TCP port 7777 with the distinctive banner <code>xlogin</code>. Later activity showed a significant increase in compromised Asus routers and the addition of new ports and banners, including TCP port 63256 displaying <code>alogin</code>. Quad7 infrastructure functions as a collection of egress IPs that various China-affiliated threat actors have used to conduct password-spraying and brute-force operations. (Citation: Bitsight 7777 Botnet)(Citation: Medium 777-Botnet) Microsoft has reported that Storm-0940 leveraged credentials obtained through Quad7 Activity to target organizations in North America and Europe, including government agencies, non-governmental organizations, think tanks, law firms, energy firms, IT providers, and defense industrial base entities. (Citation: Microsoft Storm-0940)

Start date
1 August 2023
End date
1 August 2025
Techniques
15

Attributed actors

Techniques (15)

command-and-control7
T1665Hide Infrastructure
T1105Ingress Tool Transfer
T1071.001Web Protocols
T1571Non-Standard Port
T1071.002File Transfer Protocols
T1090.003Multi-hop Proxy
T1090.002External Proxy
credential-access1
T1110.003Password Spraying
defense-impairment1
T1685Disable or Modify Tools
execution1
T1059.004Unix Shell
initial-access1
T1190Exploit Public-Facing Application
reconnaissance1
T1589.002Email Addresses
resource-development2
T1584.008Network Devices
T1584.005Botnet
stealth1
T1027.011Fileless Storage

Indicators of compromise

No IOCs linked to this campaign yet.