216.73.217.22

Botnet 7777: Are You Betting on a Compromised Router?

· Published 08/08/2024 11:30 · Modified 08/08/2024 11:38

Export JSON

Essential information

Published
08/08/2024 11:30
Modified
08/08/2024 11:38
Tags
2024-08-08 asus botnet compromised devices routers tp-link
Related entities
7 observables, 16 techniques (mitre)

Description

This analysis uncovers the expansion of a significant operation, dubbed Quad7 or 7777 , characterized by its unique use of TCP port 7777 on compromised , primarily and Hikvision devices. The research reveals a potential second tranche of bots, the 63256 , comprised mainly of infected , indicating an evolution of the threat actor's tactics. Over a 30-day period, 12,783 active bots were identified across both infrastructures, highlighting the 's substantial scale. The analysis also pinpoints seven management IP addresses associated with the 's operations, some previously undisclosed. The findings underscore the resilience and adaptability of this persistent threat, warranting continued vigilance and collaborative efforts to mitigate its impact.

External references