Skip to main content
Mallory
2 malware families

Quad7

Also known asQuad7

Quad7 is a botnet/activity cluster tracked as Quad7, CovertNetwork-1658, xlogin, and 7777. Reporting in the provided content links it to Chinese threat actors, and Sekoia assesses the activity is likely associated with a Chinese state-sponsored threat actor, although exact attribution is described as unconfirmed. The activity centers on compromising SOHO routers and other edge/network devices to build a botnet and use that infrastructure for password spraying and related follow-on operations. The content states Quad7 has compromised branded SOHO routers and other devices including TP-Link routers, ASUS routers, Zyxel VPN appliances, Ruckus Wireless devices, IP cameras, NAS devices, Dahua DVRs, MVPower devices, Zyxel NAS, and GitLab at low volume. Microsoft reported in October 2024 that the botnet was mainly composed of hacked home and small-business routers, primarily TP-Link devices, and that credentials obtained through its password spray operations were used by multiple Chinese threat actors for computer network exploitation activities. Observed tradecraft in the provided content includes exploitation of known and unknown vulnerabilities in public-facing devices, including remote code execution on TP-Link routers via CVE-2023-50224 and CVE-2025-9377; disabling the TP-Link management interface by killing /usr/bin/httpd; creating an access-controlled /bin/sh shell on compromised routers; downloading additional binaries from remote FTP servers; storing artifacts in /tmp for volatile/fileless persistence; opening non-standard TCP ports including 7777, 11288, 63256, 63260, 63210, 3256, and 3556; initializing SOCKS5 proxies; and routing traffic through chains of compromised network devices as multi-hop proxies/operational relay boxes to conceal source infrastructure. The activity has been observed conducting brute-force and password-spray attempts against Microsoft 365 and Azure instances. The password spraying is described as throttled to a single sign-in attempt per 24-hour period to evade brute-force detection thresholds, with targeted email addresses gathered in advance and compromised SOHO IP addresses rotated to hinder detection and blocking. Sign-in attempts referenced Microsoft Azure PowerShell Application ID 1950a258-227b-4e31-a9cf-717495945fc2 and used browser-like user-agent strings. The operators also introduced a backdoor named UPDTAE that establishes an HTTP-based reverse shell for remote command execution from C2. Known related clusters/sub-groups named in the content are xlogin (compromised TP-Link routers), alogin (compromised ASUS routers), rlogin (compromised Ruckus Wireless devices), zylogin (compromised Zyxel VPN appliances), and axlogin (a capability targeting Axentra NAS devices that had not been detected in the wild at the time of reporting).

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0006
Credential Access
1 technique
T1110
Brute Force
T1110.003
Password Spraying
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Quad7 | Mallory