← Back to all campaigns
ActiveMITRE ATT&CK

Quad7 Activity

Quad7 Activity, also known as CovertNetwork-1658 or the 7777 Botnet, is a network of compromised small office/home office (SOHO) routers. The botnet was initially composed primarily of TP-Link routers and was named Quad7 due to compromised devices exposing TCP port 7777 with the distinctive banner xlogin. Later activity showed a significant increase in compromised Asus routers and the addition of new ports and banners, including TCP port 63256 displaying alogin. Quad7 infrastructure functions as a collection of egress IPs that various China-affiliated threat actors have used to conduct password-spraying and brute-force operations. Microsoft has reported that Storm-0940 leveraged credentials obtained through Quad7 Activity to target organizations in North America and Europe, including government agencies, non-governmental organizations, think tanks, law firms, energy firms, IT providers, and defense industrial base entities.

First observedAug 1, 2023
Last observedAug 1, 2025
Attributed actors0
Source-backed events2
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

No actor attribution is currently available.
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Last observed
Campaign

Quad7 Activity last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Quad7 Activity first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Related vulnerabilities 0

No linked CVEs are available.

ATT&CK techniques 0

No linked techniques are available.

Malware and tools 0

No linked malware or tools are available.

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.