Storm-0940 is a Chinese threat actor active since 2021, known for gaining initial access via password spraying and edge application exploitation.
Analyst brief
Storm-0940 is a Chinese threat actor active since at least 2021, focusing on initial access via password spray, brute-force attacks, and the exploitation of network edge applications. They leverage valid credentials obtained from the closely related actor CovertNetwork-1658 (ORB07) and utilize botnets like Quad7 to facilitate their password spraying campaigns. Defenders should prioritize enforcing multi-factor authentication, robust account lockout policies against brute-force attempts, and timely patching of edge device vulnerabilities.
Storm-0940
CovertNetwork-1658ORB07
unknown
Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force attacks, as well as exploiting network edge applications. Microsoft has observed Storm-0940 utilizing valid credentials obtained from CovertNetwork-1658's password spray operations, indicating a close operational relationship between the two. Once inside a victim environment, Storm-0940 has been seen leveraging compromised credentials for further malicious activities. Additionally, Storm-0940 has employed botnets, such as Quad7, to facilitate password spraying attacks.