Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0940

Also known as: CovertNetwork-1658, ORB07, the 7777 Botnet, xlogin

Description

Storm‑0940 operates primarily by compromising TP‑Link SOHO routers that are vulnerable to recent CVEs (CVE‑2023‑50224, CVE‑2025‑9377). Once the router is exploited, the actor installs a minimal footprint backdoor—often referred to as xlogin—which opens a command shell via Telnet on TCP port 7777 and places malicious binaries in temporary directories. The botmaster then controls these infected devices through the Quad7 botnet, which leverages encrypted C2 channels over non‑standard ports such as 63256. The backdoor is used to launch widespread password‑spraying attacks against target accounts, typically making a single login attempt per day for thousands of user names. This low‑volume approach reduces chances of lockout while enabling credential theft on cloud services such as Microsoft Azure or other SaaS platforms. Credentials are then passed to the broader CovertNetwork‑1658 proxy network, where they can be reused and re‑authenticated inside victim environments. In addition to credential theft, Storm‑0940 demonstrates persistence by disabling router management interfaces (e.g., killing httpd processes) and installing command shells that remain active after reboot. Their pattern of IP rotation and use of obscure ports is designed to hide infrastructure within the botnet while facilitating rapid lateral movement once valid credentials are obtained. Overall, the actor’s operational profile indicates a blend of automation—through botnets and credential‑dumping frameworks—and manual exploitation of network edge devices, enabling both stealthy espionage and opportunistic financial attacks.

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Aviation
Healthcare
Maritime
Think tank
Construction
Legal services
Financial services
Non profit
Media

Targeted Countries / Regions

CN
IL
UA
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Storm‑0940 is a highly adaptable threat actor that exploits vulnerable consumer routers to build proxy botnets, then uses those proxies for low‑volume password spraying against Microsoft and other enterprises worldwide. The group combines credential theft with sophisticated command‑and‑control over non‑standard ports and rapid IP rotation to evade detection. Its tactics suggest alignment with state‑backed campaigns focused on financial gain and strategic espionage across a wide range of sectors.

Goals & Targeting

Storm‑0940 appears to pursue two primary objectives: first, the acquisition of privileged credentials for monetary exploitation or ransom through large‑scale password spraying; second, strategic reconnaissance across high‑value sectors such as government, defense, energy, aviation, healthcare, maritime, think‑tanks, construction, legal and financial services. The actor’s use of embedded device compromises suggests a desire to maintain low‑cost, long‑lived footholds that can pivot into internal enterprise networks once credentials are obtained.

Enhanced Description

Key Capabilities

  • Password spraying (single‑attempt per day across thousands of accounts)
  • Exploitation of router CVEs (CVE‑2023‑50224, CVE‑2025‑9377)
  • Remote code execution on TP‑Link SOHO routers
  • Installation of command shells via /bin/sh and Telnet on TCP 7777
  • Use of FTP servers for malware delivery and persistence
  • IP rotation and non‑standard port C2 (e.g., 63256, 7777)
  • Disabling router management interfaces by terminating httpd
  • Storing artifacts in /tmp directories on embedded devices
  • Utilisation of the Quad7 botnet & CovertNetwork‑1658 infrastructure
  • Persistence through compromised credentials and lateral movement

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.microsoft.com — Cited by web research for: xlogin
  2. attack.mitre.org — Cited by web research for: T1071
  3. learn.microsoft.com — Cited by web research for: Tsunami
  4. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

19

Techniques

43

Tools

0

Campaigns

8

IOCs

0

Observed Data

9

Tactics

Tags

DDoS
APT
espionage
botnet
credential-theft
Chinese-state-linked

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.