The operators of the mysterious Quad7 botnet are continuously evolving by compromising several brands of SOHO (small office/home office) routers and VPN appliances. They exploit both known and unknown security flaws, posing a significant threat to global cybersecurity.
According to a recent report by the French cybersecurity company Sekoia, targets of this malicious botnet include devices from brands such as TP-LINK, Zyxel, Asus, Axentra, D-Link, and NETGEAR.
"The Quad7 botnet operators appear to be evolving their toolset, introducing a new backdoor and exploring new protocols with the aim of enhancing stealth and evading the tracking capabilities of their operational relay boxes (ORBs)," said researchers Felix Aimé, Pierre-Antoine D., and Charles M.
First publicly documented by independent researcher Gi7w0rm in October 2023, Quad7—also known as 7777—has been primarily identified for its activity targeting TP-Link routers and Dahua digital video recorders (DVRs), incorporating these devices into a botnet.
The botnet gets its name from its practice of opening TCP port 7777 on compromised devices. Quad7 has also been observed brute-forcing Microsoft 365 and Azure instances.
"The botnet also appears to infect other systems like MVPower, Zyxel NAS, and GitLab, although at a very low volume," said Jacob Baines from VulnCheck earlier this year. "It doesn't just start a service on port 7777—it also spins up a SOCKS5 server on port 11228."
Further analysis from Sekoia and Team Cymru over the past months indicates that Quad7 has compromised TP-Link routers in Bulgaria, Russia, the U.S., and Ukraine. The botnet has since expanded its reach to target ASUS routers that have TCP ports 63256 and 63260 open.
Quad7 Botnet Clusters
The latest findings reveal that the botnet is composed of three additional clusters:
- xlogin (aka 7777 botnet): A botnet made up of compromised TP-Link routers with both TCP ports 7777 and 11228 open.
- alogin (aka 63256 botnet): A botnet consisting of compromised ASUS routers with TCP ports 63256 and 63260 open.
- rlogin: A botnet of compromised Ruckus Wireless devices with TCP port 63210 open.
- axlogin: A botnet capable of targeting Axentra NAS devices (not yet detected in the wild).
- zylogin: A botnet made up of compromised Zyxel VPN appliances with TCP port 3256 open.
Sekoia’s report notes that the countries with the highest number of infections are Bulgaria (1,093), the U.S. (733), and Ukraine (697).
New Tactics and Backdoors
In a clear sign of tactical evolution, the Quad7 threat actors have introduced a new backdoor, dubbed "UPDTAE." This backdoor allows them to establish an HTTP-based reverse shell, enabling remote control over infected devices and the execution of commands sent from a command-and-control (C2) server.
Currently, the exact purpose of the botnet remains unclear. However, Sekoia suggests that the activity is likely the work of a Chinese state-sponsored threat actor.
"Regarding the 7777 botnet, we’ve only observed brute-force attempts against Microsoft 365 accounts," Aimé told the publication. "For the other botnets, we still don’t know how they are being utilized."
Further exchanges with other researchers and additional findings suggest that the operators are more likely Chinese state-sponsored actors rather than simple cybercriminals focused on business email compromise (BEC).
"We are observing the threat actor becoming more stealthy by deploying new malware on compromised edge devices," the researchers noted. "The main goal behind this evolution appears to be preventing the tracking of affiliated botnets."