ATT&CKReferencesBitsight 7777 Botnet

Bitsight 7777 Botnet

Batista, João. Gi7w0rm. (2024, August 27). Retrieved June 5, 2025.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples5

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
CampaignQuad7 Activity

Quad7 Activity has infected victim network devices by storing artifacts in the /tmp directory which is volatile in memory and will clear its contents upon shutdown or restart.

T1059.004
Unix Shell
CampaignQuad7 Activity

Quad7 Activity has enabled the creation of an access-controlled command shell /bin/sh on compromised routers.

T1090.002
External Proxy
CampaignQuad7 Activity

Quad7 Activity has initialized SOCKS5 proxies on compromised devices.

T1584.005
Botnet
CampaignQuad7 Activity

Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity.

T1685
Disable or Modify Tools
CampaignQuad7 Activity

Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the /usr/bin/httpd process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.