216.73.216.6

Solving the 7777 Botnet enigma: A cybersecurity quest

· Published 23/07/2024 08:00 · Modified 23/07/2024 08:14

Export JSON

Essential information

Published
23/07/2024 08:00
Modified
23/07/2024 08:14
Tags
2024-07-23 botnet cybercrime iot microsocks microsoft 365 password spraying xlogin
Related entities
4 observables, 8 techniques (mitre), 2 malware

Description

Sekoia.io investigated the mysterious 7777 (aka Quad7 ), which compromised TP-Link routers to relay attacks against accounts. The investigation involved intercepting network communications and malware deployed on a compromised router in France. The findings suggest the Quad7 operators leverage these routers for possible long-term business email compromise (BEC) cybercriminal activity rather than an APT threat actor. However, some mysteries remain regarding the exploits used, the geographical distribution, and the attribution of this activity cluster.

External references