logo

Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network

ID: 0a5f5077-c845-58c3-909d-3179b40c9bfd

STIX ID: report--0a5f5077-c845-58c3-909d-3179b40c9bfd

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2024-10-31

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft observed a large, covert network of compromised SOHO routers (CovertNetwork-1658) being prepared with backdoors, Telnet, and SOCKS5 proxies to proxy low-volume password spray attacks that have supplied credentials to Chinese-linked Storm-0940; the report details attack patterns, affected sectors, observed user agents and IP behavior, detection/hunting queries, and recommended mitigations such as enforcing MFA, disabling legacy auth, and improving credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.