Quad7 is a botnet and intrusion activity cluster associated with Chinese threat actors and assessed by some researchers as likely linked to a Chinese state-sponsored operator. It is also tracked as CovertNetwork-1658, xlogin, and 7777, with related clusters including alogin, rlogin, zylogin, and a not-yet-observed capability referred to as axlogin. The activity centers on compromising internet-exposed SOHO routers, VPN appliances, and other edge devices to build an operational relay network used to conceal follow-on attacks. Quad7 has been observed compromising devices from multiple vendors, initially with heavy use of TP-Link routers and later expanding to additional router, VPN, NAS, DVR, and IP camera platforms. Reported tradecraft includes exploitation of known and unknown vulnerabilities for remote code execution, deployment of additional payloads, disabling device management services, use of volatile storage to reduce forensic visibility, and operation of reverse-shell and proxy capabilities on infected devices. A backdoor known as UPDTAE has been associated with the activity and provides HTTP-based remote command execution. The botnet’s most clearly documented operational use is password spraying against cloud identity services, including Microsoft 365 and Azure-related targets. Operators have routed traffic through chains of compromised devices, rotated source infrastructure to frustrate blocking, and throttled authentication attempts to evade brute-force detection thresholds. Quad7-infected devices have also exposed proxy services, including SOCKS5, indicating a broader role as anonymizing relay infrastructure for downstream intrusion activity. High-confidence reporting links credentials obtained through Quad7-enabled password spraying to subsequent computer network exploitation by multiple Chinese threat actors. The actor’s behavior demonstrates emphasis on stealth, defense evasion, distributed relay infrastructure, and scalable initial-access support rather than overt disruptive or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet/activity cluster built from compromised home and small-business routers (primarily TP-Link) and used by China-linked operators for credential theft and subsequent password-spray attacks, and as infrastructure to support cyber-attack operations against the United States.
Operates a botnet of compromised SOHO routers, primarily TP-Link devices, used for password spray operations that enable follow-on computer network exploitation activities.
Activity cluster operating the Quad7/7777 botnet, compromising SOHO routers/VPN appliances (e.g., TP-LINK, Zyxel, Asus, Axentra, D-Link, NETGEAR; also Ruckus Wireless) using known/unknown flaws, enabling exposed services (notably TCP 7777 and a SOCKS5 service), and conducting brute-force attempts against Microsoft 365/Azure. Recent evolution includes a new backdoor (UPDTAE) providing an HTTP-based reverse shell for remote command execution and increased stealth/anti-tracking via ORBs.
Used chains of compromised network devices to route traffic for password spraying.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.