Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Microsoft Warns of Chinese Botnet Exploiting Router Flaws to Steal Credentials
Global Security

Microsoft Warns of Chinese Botnet Exploiting Router Flaws to Steal Credentials

AdminBy AdminNovember 1, 2024No Comments3 Mins Read
Chinese Botnet
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 1, 2024Ravi LakshmananThreat Intelligence / Network Security

Chinese botnet

Microsoft has revealed that a Chinese threat actor it tracks as Storm-0940 uses a botnet called Quad7 to orchestrate highly evasive password spraying attacks.

The tech giant named the botnet CovertNetwork-1658, saying that password spraying operations are being used to steal credentials from numerous Microsoft customers.

“Active since at least 2021, Storm-0940 gains initial access through password spraying and brute force attacks, or by exploiting or misusing network applications and services,” the Microsoft Threat Intelligence team said. said.

Cyber ​​security

“Storm-0940 is known to target organizations in North America and Europe, including think tanks, government organizations, non-governmental organizations, law firms, the defense industrial base and others.”

Quad7 aka 7777 or xlogin was the item extensive analyses Sekoia and Team Cymru in recent months. The botnet malware was seen targeting several brands of SOHO routers and VPN devices, including TP-Link, Zyxel, Asus, Axentra, D-Link and NETGEAR.

These devices are recruited by exploiting known and as-yet-unknown security flaws to gain remote code execution capabilities. The name of the botnet is a reference to routers being infected with a backdoor that listens on TCP port 7777 to facilitate remote access.

Chinese botnet

Sekoia told The Hacker News in September 2024 that the botnet is primarily used to carry out brute force attempts against Microsoft 365 accounts, adding that the operators are likely Chinese state-sponsored entities.

Microsoft also assessed that botnet operatives are located in China and that several threat actors from that country are using the botnet to conduct password spraying attacks for subsequent computer network exploitation (CNE) activities such as lateral movement, deployment remote Trojan access and data theft attempts.

That includes Storm-0940, which he says infiltrated targeted organizations using valid credentials obtained from password spraying attacks, in some cases on the same day the credentials were extracted. “Rapid operational transfer” involves close cooperation between botnet operators and Storm-0940, the company said.

“CovertNetwork-1658 sends a very small number of logon attempts to many accounts in the targeted organization,” Microsoft said. “Approximately 80 percent of the time, CovertNetwork-1658 makes only one login attempt per day.”

Cyber ​​security

It is estimated that there are approximately 8,000 compromised devices active on the network at any given time, although only 20 percent of these devices are involved in password spraying.

The Windows maker also warned that the botnet’s infrastructure has seen “unsustainable and dramatic decline” since the public disclosure, raising the possibility that threat actors are “likely acquiring new infrastructure with altered fingerprints” to avoid detection.

“Any threat actor using the CovertNetwork-1658 infrastructure can conduct larger-scale password spraying campaigns and significantly increase the likelihood of successfully compromising credentials and gaining initial access to multiple organizations in a short period of time,” Microsoft said.

“This scale, combined with the rapid operational turnover of compromised credentials between CovertNetwork-1658 and Chinese threat actors, allows for the potential compromise of accounts across sectors and geographies.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.