7777-Botnet is a botnet assessed at roughly 10,000 nodes that has been used to brute-force Microsoft Azure user credentials. It has been characterized as a targeted, low-volume operation whose activity was identified through geolocation login anomalies rather than overt high-volume scanning. Reported targets include VIP users associated with organizations in the United States and Europe. The botnet remains active as of 2025. Operationally, the botnet is associated with internet-exposed edge and IoT devices, including TP-Link routers, Hikvision cameras and OEM derivatives, and Xiongmai devices. Historical exploitation evidence ties the botnet to TP-Link vulnerabilities including CVE-2023-50224 and CVE-2025-9377. Additional infection vectors involving Xiongmai, Hikvision, and older TP-Link devices have been discussed as plausible hypotheses based on co-location and exposure patterns, but those pathways are not established here as confirmed facts. Beyond its characteristic listener on port 7777, the botnet has also been observed enabling a SOCKS5 proxy service, indicating secondary use as attacker infrastructure. The actor’s demonstrated behavior supports credential brute-forcing and broader botnet-style infrastructure abuse. Public reporting has noted loose, unconfirmed links to Scattered Spider and Lazarus, but attribution to either has not been established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The 7777 botnet is associated with exploitation of TP-Link router vulnerabilities, using them to compromise devices and likely add them to a botnet for further malicious activity.
The 7777-Botnet is an active botnet primarily focused on brute-forcing Microsoft Azure user credentials, targeting VIP users in the US and Europe. It infects IoT and network devices (TP-Link, Xiongmai, Hikvision, etc.) using known vulnerabilities, and spins up SOCKS5 proxies for further operations. There are loose links to threat actors Scattered Spider and Lazarus, but attribution is not definitive.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.