Quad7 Activity is an intrusion activity cluster associated with compromises of network edge devices and their subsequent use as operational relay infrastructure for credential attacks. The activity is characterized by infecting victim network devices, storing artifacts in volatile temporary storage to reduce forensic residue, enabling an access-controlled command shell, and initializing SOCKS5 proxy services on compromised devices. Operators have routed traffic through chains of compromised network devices to obscure origin and support follow-on operations. A defining tradecraft element is low-and-slow password spraying. Quad7 Activity has gathered targeted individuals’ email addresses and used a throttled spraying pattern limited to a single sign-in attempt per account within a 24-hour period, a cadence designed to remain below common brute-force detection thresholds. The combination of proxy chaining across compromised devices, transient artifact storage, remote shell access, and carefully paced authentication attempts indicates an emphasis on defense evasion and durable access to intermediary infrastructure rather than noisy direct intrusion. Known reporting identifies this cluster under the name Quad7 Activity. High-confidence public facts support its use of compromised network devices as proxy nodes and relay infrastructure for password-spraying operations, but do not firmly establish a specific national attribution, victim-country set, or industry concentration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sets up SOCKS5 proxy services on compromised devices.
Activity cluster infecting victim network devices and storing artifacts in volatile /tmp storage for reduced persistence on reboot.
Conducts highly throttled password spraying (one attempt per account per 24 hours) to evade brute-force detection thresholds.
Establishes SOCKS5 proxy services on compromised devices for traffic tunneling/relay.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.