HomeSecurityChinese hackers use Quad7 botnet to steal credentials

Chinese hackers use Quad7 botnet to steal credentials

Microsoft warns that Chinese hackers are using the Quad7 botnet to steal credentials in password-spray attacks .

Quad7 botnet Chinese hackers

The Quad7 botnet, also known as CovertNetwork-1658 or xlogin, was discovered by security Gi7w0rm and consists primarily of compromised SOHO routers.

Subsequent reports from Sekoia and Team Cymru indicated that the attackers were targeting routers and networking devices from TP-Link, ASUS, Ruckus, Axentra, and Zyxel.

When devices are compromised, attackers deploy custom malware that allows remote access to the devices via Telnet. Then, unique welcome banners are displayed based on the compromised device:

  • xlogin – Telnet connected to TCP port 7777 on TP-Link routers
  • alogin – Telnet connected to TCP port 63256 on ASUS routers
  • rlogin – Telnet connected to TCP port 63210 on Ruckus wireless devices
  • axlogin – Telnet banner on Axentra NAS devices (unknown port)
  • zylogin – Telnet connected to TCP port 3256 on Zyxel VPN devices

Attackers install a SOCKS5 proxy server that is used to proxy or transmit malicious attacks, while combining it with legitimate traffic to avoid detection.

See also: Mirai-inspired Gorilla Botnet hits 0.3 million targets in 100 countries

The Quad7 botnet has not been linked to any specific hacking group so far . Team Cymru tracked the proxy software used on routers and traced it to a user living in Hangzhou, China.

Chinese hackers use Quad7 botnet to steal credentials

Quad7 botnet steals credentials through password-spray attacks

Microsoft revealed that the Quad7 botnet is likely operating from China, with many Chinese hackers using the compromised routers to steal credentials through password spray attacks.

Microsoft assesses that credentials obtained from Quad7 password spray attacks are being used by multiple Chinese threat actors,” Microsoft says in a new report.

Specifically, Microsoft observed Chinese hackers Storm-0940 using credentials from Quad7“.

When carrying out the attacks, the Chinese hackers only try to log in to each account a few times. They don't get very persistent, likely to avoid triggering any alarms.

In these campaigns, Quad7 proceeds with a very small number of login attempts, across multiple accounts in a target organization,” Microsoft says.

See also: Mirai-inspired Gorilla Botnet hits 0.3 million targets in 100 countries

However, after stealing the credentials, the Chinese Storm-0940 hackers immediately use them to compromise targeted networks. Once the network is compromised, the threat actors spread further and install RATs and tools proxy

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The ultimate goal of the attack is to steal data from the targeted network, possibly for cyberespionage.

To date, researchers have not determined exactly how the attackers behind the Quad7 botnet compromise SOHO routers and other network devices. However, Sekoia observed that one of their honeypots was compromised by threat actors using a zero-day in OpenWRT.

credentials

Protection against botnet

To protect yourself from Botnets, it is important to keep software and operating system up to date. Botnet attacks often exploit known vulnerabilities.

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: Quad7 botnet targets more VPN routers, media servers

Using strong passwords and changing them regularly is another way to protect yourself from Botnets (e.g. Quad7). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect accounts .

Finally, information security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS