Storm-0940
Aliases: CovertNetwork-1658, ORB07
- First seen
- 2021-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:34:20
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Targeted regions: country_code:us country_code:au country_code:gb
Context
Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force attacks, as well as exploiting network edge applications. Microsoft has observed Storm-0940 utilizing valid credentials obtained from CovertNetwork-1658's password spray operations, indicating a close operational relationship between the two. Once inside a victim environment, Storm-0940 has been seen leveraging compromised credentials for further malicious activities. Additionally, Storm-0940 has employed botnets, such as Quad7, to facilitate password spraying attacks.
Reports & references
- Microsoft — Chinese Threat Actor Storm 0940 Uses Credentials From Password Spray Attacks From A Covert Network (report)
- raw.githubusercontent.com — Microsoftmapping (report)