Microsoft Threat Intelligence. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. Retrieved June 4, 2025.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
CampaignQuad7 Activity | Quad7 Activity has enabled the creation of an access-controlled command shell |
| T1071.001 Web Protocols |
CampaignQuad7 Activity | Quad7 Activity has used the same User Agents of |
| T1071.002 File Transfer Protocols |
CampaignQuad7 Activity | Quad7 Activity has used a File Transfer Protocol (FTP) server to download malicious binaries. |
| T1090.002 External Proxy |
CampaignQuad7 Activity | Quad7 Activity has initialized SOCKS5 proxies on compromised devices. |
| T1090.003 Multi-hop Proxy |
CampaignQuad7 Activity | Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks. |
| T1105 Ingress Tool Transfer |
CampaignQuad7 Activity | Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices. |
| T1110.003 Password Spraying |
CampaignQuad7 Activity | Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds. |
| T1190 Exploit Public-Facing Application |
CampaignQuad7 Activity | Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices. |
| T1571 Non-Standard Port |
CampaignQuad7 Activity | Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2. |
| T1584.005 Botnet |
CampaignQuad7 Activity | Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity. |
| T1584.008 Network Devices |
CampaignQuad7 Activity | Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity. |
| T1665 Hide Infrastructure |
CampaignQuad7 Activity | Quad7 Activity has rotated the compromised SOHO IPs used in password spraying activity to hamper detection and network blocking activities by defenders. |
| T1685 Disable or Modify Tools |
CampaignQuad7 Activity | Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.