logo

Microsoft: Chinese hackers use Quad7 botnet to steal credentials

ID: 2486fba1-b4a3-5457-9368-0afed643152f

STIX ID: report--2486fba1-b4a3-5457-9368-0afed643152f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-31

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

**Executive Summary:** Microsoft and multiple security researchers describe Quad7 (aka CovertNetwork-1658 / xlogin), a botnet of compromised SOHO routers (TP-Link, ASUS, Ruckus, Axentra, Zyxel) that deploys Telnet-based backdoors and SOCKS5 proxies; the infrastructure is being used in low-noise password-spray campaigns to steal credentials that Chinese threat actors (notably Storm-0940) then use to breach networks, move laterally, install RATs/proxies for persistence, and exfiltrate data, with at least one observed chain involving an OpenWRT zero-day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.