Quad7 botnet targets more SOHO and VPN routers, media servers
ID: 1e31ed89-74f0-5072-8c91-07827b8ff90d
STIX ID: report--1e31ed89-74f0-5072-8c91-07827b8ff90d
Feed Name: Bleeping Computer
The Quad7 botnet is expanding and evolving: researchers observed distinct subclusters (xlogin, alogin, rlogin, zylogin, axlogin) targeting various SOHO devices (TP-Link, ASUS, Ruckus, Zyxel, Axentra) using Telnet-accessible banners/ports, while operators adopt stealthier communications (KCP/FsyNet over UDP), a new UPDTAE HTTP reverse-shell backdoor, and experimental darknet-like CJD route2 mechanisms; some clusters contain thousands of devices, others are small or experimental, and the report includes device-specific IoCs and mitigation guidance (update firmware, change defaults, disable unused admin interfaces).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
