ADVERTISEMENT

Wifi routers and VPN appliances targeted by notorious botnet Quad7

The mysterious Quad7 botnet has evolved its tactics to compromise several brands of Wi-Fi routers and VPN appliances. It’s armed with new backdoors, multiple vulnerabilities, some of which were previously unknown, and new staging servers and clusters, according to a report by Sekoia, a cybersecurity firm.

router office

Image from Shutterstock

Ernestas Naprys
Ernestas Naprys Senior Journalist
September 10, 2024 2 min read
  • xlogin botnet, composed of compromised TP-Link routers that have both TCP ports TELNET/7777 and 11288 open.
  • rlogin botnet, targeting Ruckus Wireless devices with exposed TCP port TELNET/63210.
  • alogin botnet, composed of compromised Asus routers that have both TCP ports 63256 and 63260 open.
  • axlogin botnet, which appears to be deployed on Axentra NAS. It’s unclear which port may be targeted as the obtained malware sample was not observed in the wild.
  • zlogin botnet, deployed on Zyxel VPN appliances, listening to the port TELNET/3256
ADVERTISEMENT
ADVERTISEMENT