Microsoft: Chinese hackers use Quad7 botnet to steal credentials

Share:

Microsoft warns that Chinese threat actors use the Quad7 botnet, compromised of hacked SOHO routers, to steal credentials in password-spray attacks.

Quad7, also known as CovertNetwork-1658 or xlogin, is a botnet first discovered by security researcher Gi7w0rm that consists of compromised SOHO routers.

Later reports by Sekoia and Team Cymru reported that the threat actors are targeting routers and networking devices from TP-Link, ASUS, Ruckus wireless devices, Axentra NAS devices, and Zyxel VPN appliances.

When the devices are compromised, the threat actors deploy custom malware that allows remote access to the devices over Telnet, which display unique welcome banners based on the compromised device:

  • xlogin – Telnet bound to TCP port 7777 on TP-Link routers
  • alogin – Telnet bound to TCP port 63256 on ASUS routers
  • rlogin – Telnet bound to TCP port 63210 on Ruckus wireless devices.
  • axlogin – Telnet banner on Axentra NAS devices (port unknown as not seen in the wild)
  • zylogin – Telnet bound to TCP port 3256 on Zyxel VPN appliances

Other installed, the threat actors install a SOCKS5 proxy server that is used to proxy, or relay, malicious attacks while blending in with legitimate traffic to evade detection.

Quad7 botnet devices and what they are used for
Quad7 botnet devices and what they are used for
Source: Sekoia

While the botnet had not been attributed to a particular threat actor, Team Cymru tracked the proxy software used on these routers to a user living in Hangzhou, China.

Quad7 botnet used for password-spray attacks

Microsoft disclosed today that the Quad7 botnet is believed to operate from China, with multiple Chinese threat actors utilizing the compromised routers to steal credentials through password spray attacks.

“Microsoft assesses that credentials acquired from CovertNetwork-1658 password spray operations are used by multiple Chinese threat actors,” Microsoft says in a new report.

“In particular, Microsoft has observed the Chinese threat actor Storm-0940 using credentials from CovertNetwork-1658.”

When conducting the password spray attacks, Microsoft says the threat actors are not aggressive, only attempting to log in a few times per account, likely to avoid triggering any alarms.

“In these campaigns, CovertNetwork-1658 submits a very small number of sign-in attempts to many accounts at a target organization,” shared Microsoft.

“In about 80 percent of cases, CovertNetwork-1658 makes only one sign-in attempt per account per day.”

CovertNetwork-1658 count of sign-in attempts per account per day.
CovertNetwork-1658 count of sign-in attempts per account per day.
Source: Microsoft

However, once credentials are stolen, Microsoft has observed Storm-0940 utilizing them to breach targeted networks, sometimes on the same day they were stolen.

Once the network is breached, the threat actors spread further through the network by dumping credentials and installing RATs and proxy tools for persistence on the network.

The ultimate goal of the attack is to exfiltrate data from the targeted network, likely for cyber espionage purposes.

To this day, researchers have not determined precisely how the Quad7 threat actors are compromising SOHO routers and other network devices.

However, Sekoia observed one of their honeypots being breached by the Quad7 threat actors utilizing an OpenWRT zero-day.

“We waited less than a week before observing a notable attack that chained an unauthenticated file disclosure which seems to be not public at this time (according to a Google search) and a command injection,” explained Sekoia in July.

How the threat actors are breaching other devices remains a mystery.

Lawrence Abrams

 

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:16 pm, Jun 28, 2025
weather icon 29°C
L: 28° | H: 30°
few clouds
Humidity: 52 %
Pressure: 1023 mb
Wind: 11 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
28° | 30°°C 0 mm 0% 11 mph 57 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 7 mph 83 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 36°°C 1 mm 100% 8 mph 67 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 32°°C 0.74 mm 74% 12 mph 73 % 1019 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 18 mph 85 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 29°°C 0 mm 0% 11 mph 52 % 1023 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 27°°C 0 mm 0% 8 mph 57 % 1024 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 23°°C 0 mm 0% 7 mph 68 % 1024 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 83 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 75 % 1025 mb 0 mm/h
Tomorrow 10:00 am
weather icon
24° | 24°°C 0 mm 0% 5 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 6 mph 40 % 1024 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
31° | 31°°C 0 mm 0% 5 mph 33 % 1023 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,581.63
0.04%
Ethereum(ETH)
€2,078.28
0.47%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
4.26%
Solana(SOL)
€127.49
4.25%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.139008
1.23%
Shiba Inu(SHIB)
€0.000009
1.23%
Pepe(PEPE)
€0.000008
1.49%
Scroll to Top