7777-Botnet is an active botnet first publicly discussed in October 2023 in a writeup titled "The Curious Case of the 7777-Botnet." Reporting described it as an approximately 10,000-node botnet used to brute-force Microsoft Azure user credentials, with targets including VIP users from organizations in the United States and Europe. The botnet was reportedly identified through geolocation login anomalies. Earlier reporting also noted loose reported links to Scattered Spider and Lazarus, though these links were described as loose rather than confirmed. VulnCheck later reported that the botnet remains active.
Based on VulnCheck IP intelligence and co-located service observations, the botnet likely spreads by exploiting internet-exposed edge and IoT devices. High-confidence observed or assessed infection vectors include Xiongmai devices potentially via CVE-2017-7577, CVE-2018-10088, and/or CVE-2022-45460; Hikvision cameras and OEM derivatives likely via CVE-2021-36260; and older TP-Link routers possibly via CVE-2022-24355. Lower-volume co-location was also observed with MVPower, Zyxel NAS, and GitLab systems, suggesting possible use of CVE-2016-20016, CVE-2020-9054, and CVE-2021-22205, although the reporting notes some of these observations may be uncertain.
Operationally, the botnet exposes a service on port 7777 and, beyond that, often starts a SOCKS5 proxy service on port 11288. One cited example involved IP address 1.34.97.9 in Hsinchu, Taiwan, where VulnCheck observed port 7777 associated with 7777-Botnet command-and-control and a co-located Xiongmai HTTP service on port 81. Shadowserver reporting also references systems compromised by the 7777 botnet and recommends immediate action on affected hosts.
Recommended response actions in the reporting include isolating infected hosts, remediating potentially exploited vulnerabilities, validating that no additional infected devices are present, and reducing unnecessary internet exposure by placing devices behind appropriate security controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed... describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials... The botnet doesn’t just start a service on port 7777. It also spins up a SOCKS5 server on port 11228.
The other vulnerability had no CVE when VulnCheck reviewed the evidence, but was assigned CVE-2025-9377 several days later. TP-Link updated their advisory, and both CVEs were added to CISA KEV on September 3.
TP-Link CVE-2023-50224 ... tied ... to the 7777 botnet
In October 2023, the 7777-Botnet was first discussed... describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials... The botnet doesn’t just start a service on port 7777. It also spins up a SOCKS5 server on port 11228.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
In October 2023, the 7777-Botnet was first discussed in a writeup titled, The Curious Case of the 7777-Botnet. The author, supported by other researchers, describes a ~10,000 node botnet that's purpose is to brute-force Microsoft Azure user credentials.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
In our IP intelligence JSON, we are able to correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460. | 7777-Botnet remains active, and VulnCheck used co-located services to theorize the botnet is infecting TP-Link, Xiongmai, and Hikvision devices using CVE-2017-7577, CVE-2018-10088, CVE-2022-45460, CVE-2021-36260, and/or CVE-2022-24355.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet referenced as affecting certain systems (including Zyxel CPE devices); specific capabilities, infection chain, and payloads are not described in the provided content.
A botnet referenced as compromising systems; no further operational details are provided in the content.
An IoT-associated botnet with a distinct signature that is reported to brute-force Microsoft Azure user credentials (targeting VIP users in the US and Europe). It exposes a service on TCP/7777 and often starts a SOCKS5 proxy service (reported on TCP/11288 in later observations). It is hypothesized to spread by exploiting known n-day vulnerabilities in internet-exposed devices/services (notably TP-Link routers, Xiongmai devices, and Hikvision cameras).
A botnet described as remaining active and primarily known for brute-forcing Microsoft Azure user credentials using targeted, low-volume methods. It also appears to infect internet-exposed devices and can spin up a SOCKS5 server on port 11288.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.