Microsoft: Chinese hackers use Quad7 botnet to steal credentials
ID: 2486fba1-b4a3-5457-9368-0afed643152f
STIX ID: report--2486fba1-b4a3-5457-9368-0afed643152f
Feed Name: Bleeping Computer
**Executive Summary:** Microsoft and multiple security researchers describe Quad7 (aka CovertNetwork-1658 / xlogin), a botnet of compromised SOHO routers (TP-Link, ASUS, Ruckus, Axentra, Zyxel) that deploys Telnet-based backdoors and SOCKS5 proxies; the infrastructure is being used in low-noise password-spray campaigns to steal credentials that Chinese threat actors (notably Storm-0940) then use to breach networks, move laterally, install RATs/proxies for persistence, and exfiltrate data, with at least one observed chain involving an OpenWRT zero-day.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
