Password spraying is a type of brute force attack where an attacker attempts to access multiple user accounts by trying a small number of common passwords across many usernames.
This method is useful as it avoids triggering account lockouts that typically occur when multiple incorrect passwords are attempted on a single account.
Microsoft Threat Intelligence team recently discovered that Chinese hackers have been actively attacking Microsoft customers with sophisticated password spray attacks.
Since “August 2023” the Chinese threat actors dubbed “Storm-0940” have been directing sophisticated cyberattacks using a network of compromised SOHO routers by TP-Link.
All these are collectively termed as “CovertNetwork-1658” (aka ‘xlogin’ and ‘Quad7’).
This network operates by exploiting router vulnerabilities to gain RCE capabilities after which the threat actors install specific tools like “Telnet binary,” “xlogin backdoor,” and “SOCKS5 server” running on TCP ports ‘7777’ and ‘11288.’
Build an in-house SOC or outsource SOC-as-a-Service -> Calculate Costs
Threat actors employ a highly evasive technique called “password spray attacks,” where they make minimal login attempts across multiple accounts to avoid detection, using thousands of “rotating IP addresses” with an average uptime of “90 days.”
These compromised credentials were then used to target various high-profile organizations across “North America” and “Europe.”
The organizations are like:-
Following public exposure by security vendors like “Sekoia” and “Team Cymru” in mid-2024, the usage of the original infrastructure dropped remarkably.
However, Microsoft estimates that the threat actors are likely adapting their infrastructure with “modified fingerprints” to continue their operations.
Microsoft’s security monitoring has identified a sophisticated cyber threat network called “CovertNetwork-1658,” which consistently maintains control over 8,000 compromised computers, with approximately 20% of these devices simultaneously conducting password-spraying attacks.
The network’s infrastructure is used by Chinese threat actors “Storm-0940,” who demonstrate an alarmingly efficient operation where compromised credentials are exploited within the same day of the theft.
Here specific browser identifiers (User Agent Strings) were used by the threat actors including “Mozilla/5.0” for Windows 10 systems with “Chrome” and “Internet Explorer” browsers to conduct their attacks.
Once Storm-0940 gains initial access to a target organization’s network using these stolen credentials, they employ a systematic approach:-
This affects “multiple sectors” and “geographical regions globally.”
Here below we have mentioned all the recommendations:-
Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…