Storm-0940 is a Chinese threat actor assessed to conduct cyberespionage-oriented intrusions. The actor has been linked to use of the CovertNetwork-1658 botnet, also known as Quad7 or xlogin, to support highly evasive password-spray operations against target organizations. These campaigns rely on compromised small-office/home-office routers and other networking devices as proxy infrastructure, enabling low-volume authentication attempts that blend into normal traffic and reduce detection. Storm-0940 has been observed using credentials obtained through these password-spray operations to gain access to victim environments, sometimes shortly after the credentials were stolen. Following initial access, the actor conducts internal credential dumping, lateral movement, and installs remote access trojans and proxy tooling to maintain persistence and facilitate follow-on operations. Reported end objectives include data exfiltration, with activity assessed as likely motivated by espionage rather than financially driven extortion. The actor is associated with Chinese state-sponsored activity in public reporting. Known naming in the supplied material identifies the group as Storm-0940; no additional high-confidence aliases or sub-groups are established there. Storm-0940 is notable for operational use of router-based botnet infrastructure to enable stealthy credential attacks and subsequent post-compromise exploitation of enterprise networks, including U.S. corporate environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed Chinese threat actor behind activity involving CovertNetwork-1658/Quad7, used to conduct highly evasive password spray attacks.
Storm-0940 is a state-sponsored group known for recruiting TP-Link routers into a botnet to conduct evasive password spraying attacks targeting US corporate networks.
Uses credentials obtained via the Quad7/CovertNetwork-1658 botnet’s password-spray operations to breach target networks, then dumps credentials, installs RATs and proxy tools for persistence, and exfiltrates data for likely cyber espionage.
China-linked actor using a covert network of compromised SOHO routers/network devices (CovertNetwork-1658/Quad7) to password-spray, steal credentials, move laterally, and exfiltrate data across targets in North America and Europe.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.