EXECUTIVE SUMMARY
An investigation has uncovered a botnet involved in targeted attacks across the US, UK, and France, comprising over 16,000 infected devices at its peak. The botnet employs brute-forcing techniques on Microsoft Azure instances via PowerShell, uniquely opening port 7777 on compromised devices and displaying an "xlogin:" message. These low-volume attacks, typically limited to 2-3 login attempts per week, focus on C-level executives across diverse sectors. This minimal activity enables the botnet to evade detection by most security tools. While connections to known cybercriminal groups have been suggested, no definitive attribution has been established due to limited evidence.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
An investigation has uncovered a botnet involved in targeted attacks across the US, UK, and France, comprising over 16,000 infected devices at its peak. The botnet employs brute-forcing techniques on Microsoft Azure instances via PowerShell, uniquely opening port 7777 on compromised devices and displaying an "xlogin:" message. These low-volume attacks, typically limited to 2-3 login attempts per week, focus on C-level executives across diverse sectors. This minimal activity enables the botnet to evade detection by most security tools. While connections to known cybercriminal groups have been suggested, no definitive attribution has been established due to limited evidence.[emaillocker id="1283"]
Findings reveal the botnet primarily infects IoT devices such as TP-Link routers, Dahua digital video recorders, and HKVision software, often linked to residential IPs. Many of these devices were identified in specific regions, with one ISP providing a vulnerable router model to clients. The botnet's activity pattern surfaced months ago, quickly growing to over 16,000 devices before declining significantly. Its unique signature—a consistently open port 7777—allowed researchers to identify compromised devices using tools like Shodan. Despite these insights, the botnet’s low attack volume and targeted nature make detection challenging, as it avoids triggering standard security measures.
Efforts to analyze the botnet further included collaboration with researchers and attempts to reverse-engineer infected devices, but key information, such as malware samples or command-and-control infrastructure details, remains elusive. Observations suggest a focus on compromising high-value individuals, likely for financial gain, but no clear motive or actor has been confirmed. Sharing these findings aims to alert organizations to the threat, provide actionable indicators for identifying potential compromises, and inspire further research to uncover the botnet’s origins and mechanisms.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1078 | Valid Accounts |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1098 | Account Manipulation |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1110 | Brute Force |
| Discovery | T1046 | Network Service Discovery |
| Command and Control | T1071 | Application Layer Protocol |
| Impact | T1496 | Resource Hijacking |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]