Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network
ID: 0a5f5077-c845-58c3-909d-3179b40c9bfd
STIX ID: report--0a5f5077-c845-58c3-909d-3179b40c9bfd
Feed Name: Microsoft Security
Threat Score
Microsoft observed a large, covert network of compromised SOHO routers (CovertNetwork-1658) being prepared with backdoors, Telnet, and SOCKS5 proxies to proxy low-volume password spray attacks that have supplied credentials to Chinese-linked Storm-0940; the report details attack patterns, affected sectors, observed user agents and IP behavior, detection/hunting queries, and recommended mitigations such as enforcing MFA, disabling legacy auth, and improving credential hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
