Quad7 Botnet Expands with Addition of SOHO and VPN Routers and Media Servers

According to several security researchers who have been closely monitoring the malware’s recent development, the Quad7 botnet operators have been busy adding new features and expanding their attack surface.

Quad7 was first spotted by a researcher alias Gi7w0rm and experts from Sekoia, when it was only observed targeting TP-Link routers. However, in the following weeks, Quad7 (so named because it targeted port 7777) expanded to ASUS routers and has now been observed on Zyxel VPN endpoints, Ruckus wireless routers, and Axentra media servers.