Quad7 Botnet

General News

Summary

Cybersecurity specialists have identified a Chinese threat actor, known as Storm-0940, utilizing a botnet named Quad7 to conduct sophisticated and evasive password spray attacks. Operating since at least 2021, Storm-0940 gains initial access by employing password spray and brute-force techniques or by targeting vulnerabilities and misconfigurations in network edge applications and services. Storm-0940 is recognized for its focus on organizations across North America and Europe, including think tanks, governmental bodies, NGOs, law firms, and sectors within the defense industry. Microsofts assessment suggests that the botnets operators are based in China, where several threat actors utilize it for password spray attacks to enable further network exploitation. Utilizing the CovertNetwork-1658 infrastructure enables any threat actor to launch password-spraying campaigns on a much larger scale, significantly enhancing the chances of successfully compromising credentials and gaining initial access to numerous organizations in a short period.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M