Hackers working on behalf of the Chinese government are using a botnet of thousands of routers, cameras, and other Internet-connected devices to perform password spray attacks against users of Microsoft's Azure cloud service.
The botnet, known as Botnet-7777, is primarily composed of TP-Link routers and has been active since October 2023.
The attackers employ a technique called password spraying, which involves sending numerous login attempts from different IP addresses to evade detection.
This account-takeover campaign is challenging to detect due to the distributed nature of compromised devices within the botnet.