TGViewer
📜 Чтиво 📜 📜 Чтиво 📜 @chtivvvo · 137 subscribers
Post #1464 140
https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/



The malicious network, made up almost entirely of TP-Link routers, was first documented in October 2023 by a researcher who named it Botnet-7777. The geographically dispersed collection of more than 16,000 compromised devices at its peak got its name because it exposes its malicious malware on port 7777.


In July and again in August of this year, security researchers from Serbia and Team Cymru reported the botnet was still operational. All three reports said that Botnet-7777 was being used to skillfully perform password spraying, a form of attack that sends large numbers of login attempts from many different IP addresses. Because each individual device limits the login attempts, the carefully coordinated account-takeover campaign is hard to detect by the targeted service.
Ars Technica Thousands of hacked TP-Link routers used in yearslong account takeover attacks The botnet is being skillfully used to launch "highly evasive" password-spraying attacks.
  • 👍 1
More from @chtivvvo
  1. Dec 3, 2024Novel phishing campaign uses corrupted Word documents to evade security A novel phishing a…
  2. Nov 18, 2024Phishing emails increasingly use SVG attachments to evade detection Threat actors increasi…
  3. Oct 31, 2024https://sharpsec.run/rce-vulnerability-in-qbittorrent/
  4. Oct 11, 2024https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
  5. Oct 9, 2024https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-u…
  6. Sep 13, 2024LoL ))) reCAPTCHA Phish
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →