A glimpse into the Quad7 operators' next moves and associated botnets
ID: eb92192d-2b8e-53e4-835c-7f0731259b22
STIX ID: report--eb92192d-2b8e-53e4-835c-7f0731259b22
Feed Name: Sekoia.com
Threat Score
This Sekoia.io blogpost analyzes the Quad7 operators' evolving IoT botnet ecosystem (xlogin/7777, alogin/63256, rlogin/63210, axlogin, zylogin), documents newly observed HTTP reverse shells (UPDTAE), and describes emerging relay projects (FsyNet using KCP, and netd using CJDNS) intended to improve stealth and anonymization; the report includes IOCs (IPs, hashes), YARA and Snort/Suricata rules and assesses active abuse for brute-force and proxying operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
