Also known as: CovertNetwork-1658, ORB07, the 7777 Botnet, xlogin
Storm‑0940 operates primarily by compromising TP‑Link SOHO routers that are vulnerable to recent CVEs (CVE‑2023‑50224, CVE‑2025‑9377). Once the router is exploited, the actor installs a minimal footprint backdoor—often referred to as xlogin—which opens a command shell via Telnet on TCP port 7777 and places malicious binaries in temporary directories. The botmaster then controls these infected devices through the Quad7 botnet, which leverages encrypted C2 channels over non‑standard ports such as 63256. The backdoor is used to launch widespread password‑spraying attacks against target accounts, typically making a single login attempt per day for thousands of user names. This low‑volume approach reduces chances of lockout while enabling credential theft on cloud services such as Microsoft Azure or other SaaS platforms. Credentials are then passed to the broader CovertNetwork‑1658 proxy network, where they can be reused and re‑authenticated inside victim environments. In addition to credential theft, Storm‑0940 demonstrates persistence by disabling router management interfaces (e.g., killing httpd processes) and installing command shells that remain active after reboot. Their pattern of IP rotation and use of obscure ports is designed to hide infrastructure within the botnet while facilitating rapid lateral movement once valid credentials are obtained. Overall, the actor’s operational profile indicates a blend of automation—through botnets and credential‑dumping frameworks—and manual exploitation of network edge devices, enabling both stealthy espionage and opportunistic financial attacks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑0940 is a highly adaptable threat actor that exploits vulnerable consumer routers to build proxy botnets, then uses those proxies for low‑volume password spraying against Microsoft and other enterprises worldwide. The group combines credential theft with sophisticated command‑and‑control over non‑standard ports and rapid IP rotation to evade detection. Its tactics suggest alignment with state‑backed campaigns focused on financial gain and strategic espionage across a wide range of sectors.
Goals & Targeting
Storm‑0940 appears to pursue two primary objectives: first, the acquisition of privileged credentials for monetary exploitation or ransom through large‑scale password spraying; second, strategic reconnaissance across high‑value sectors such as government, defense, energy, aviation, healthcare, maritime, think‑tanks, construction, legal and financial services. The actor’s use of embedded device compromises suggests a desire to maintain low‑cost, long‑lived footholds that can pivot into internal enterprise networks once credentials are obtained.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
19
Techniques
43
Tools
0
Campaigns
8
IOCs
0
Observed Data
9
Tactics