This episode of Darknet Diaries recounts a multi-year campaign by Chinese state-sponsored hackers against Sophos, a major cybersecurity vendor. The story begins in 2018, when attackers breached Sophos's newly acquired Cyberoam division and stole firewall source code. That theft enabled years of vulnerability hunting, culminating in 2020 with a SQL injection flaw that infected roughly 80,000 internet-facing Sophos XG Firewalls and pointed them at fake update domains. Sophos responded aggressively, issuing its first-ever hot fix, seizing malicious domains through ICANN, and working with Dutch authorities to capture the attacker's command-and-control server.
Sophos then deployed a covert kernel implant on threat actor devices, gaining rare visibility into exploit development and identifying individuals including "G-Big-Mao" and "T-Stark," linked to Chinese security contractors in Chengdu. The campaign, named Pacific Rim, eventually involved at least four zero-days, rootkits, and bootkit experimentation, with attacks targeting government, healthcare, and Uyghur and Tibetan diaspora organizations. Sophos publicly disclosed the incidents, though patch notes grew deliberately vague to avoid informing attackers. One perpetrator was later placed on the FBI's Cyber Most Wanted list with a $10 million bounty, and the campaign continues.
This episode is sponsored by NetSuite.
AI isn't just opening new business opportunities,
it's changing the way businesses get work done.
That's the idea behind NetSuite Next,
the next generation of the business management suite
trusted by over 44,000 companies
with AI woven into every tool you already rely on.
NetSuite Next surfaces insights when you need them,
puts agents to work on routine tasks and problems.
It's the service that I would use if I needed it.
And if you want ideas for what else it can do for you,
experts have created a business guide
called Aligning for the Agentic Era,
how AI is changing everyday work.
And right now it's a free download
and see how AI could reshape across your organization
and how you can prosper from it.
If your revenues are at least in the seven figures,
go to netsuite.com slash darknet,
get your free guide at netsuite.com slash darknet,
netsuite.com slash darknet,
netsuite.com slash darknet.
Hi, I'm Jack Recyder, host of the show.
Back in 2018, an interesting cyber attack took place.
It's kind of a funny thing.
I mean, it basically came onto my radar
the second month I was working at Sophos.
Oh, I should introduce you to Andrew.
Yeah, so I'm Andrew Brandt.
And throughout the time that the research was going on
for this story, I was a principal researcher
for Sophos, but I am now a principal threat researcher
for a company called Netcraft.
So one of the things Sophos wanted Andrew to do
was research novel threats and write about them
on their newly established Sophos blog.
The team that I was on eventually didn't exist.
I was the only person on it.
And one of the analysts reached out to me
through the company chat and said,
hey, I've got a great story for some really cool research.
I'd like to write it up
and have you publish it on the blog
and do some edits on it.
I said, great, tell me more.
And he told me the story,
but the one thing he didn't tell
or what he said he couldn't tell me
was who the target was.
So he's like, okay, fine, send me what you got,
let me research it, and I'll write about it.
It started with a TV set.
So there was a sales office
and they had a bullpen,
like you have in a lot of sales offices
where people are on the phone trying to sell the product.
And so they had like this leaderboard
that was on a computer screen
that was running off a little Linux computer.
And that was the first machine that got infected.
And the threat actors managed to pivot from that Intel NUC,
which is like a tiny little computer
that's small enough it can mount on the back of a TV monitor
that's hanging on the wall,
that they were able to pivot from the NUC
and find access to the repository
where the source code was and then get into that.
And then to do the cloud snooper attack
on that cloud service where the source code was,
it's just mind-boggling to me.
Like the amount of effort involved
in pivoting from this to this to this
to get into this
and then to build this like backdoor
that allows them access.
It's amazing to me.
Oof, the attackers got access to the source code.
But why?
Was this an insider trying to seek revenge?
Were they stealing it in hopes to sell it
to someone?
Did they steal it so that they could copy the product
and steal their intellectual property?
At the time, nobody knew what their motive was.
These are true stories from the dark side of the internet.
I'm Jack Recider.
This is Darknet Diaries.
We'll be right back.
We'll be right back.
We'll be right back.
We'll be right back.
Because you're a Darknet Diaries listener,
they've got a little something extra waiting for you
at blackhillsinfosec.com slash darknet.
That's blackhillsinfosec.com slash darknet.
This episode is sponsored by Vanta.
As AI adoption grows,
so do your company's security risks and requirements.
New frameworks, audits, and vendors keep piling on,
but your team isn't getting any bigger.
Most compliance tools promise automation,
but you're really stuck doing all the work by hand,
chasing screenshots, validating controls,
and playing catch-up when audit season
is coming around the corner again.
Vanta works differently.
Their agentic trust platform is built to scale with you,
not slow you down.
With over 1,400 automated tests across 400-plus integrations,
Vanta collects evidence and monitors your controls year-round,
cutting your audit prep by 82%.
Plus, you can access the Vanta agentics,
which will help you get the most out of your Vanta system.
You don't have to be a Vanta agent everywhere you work,
whether your team is in Vanta every day
or living in tools like Cloud or Cursor.
Want proof?
Over 16,000 fast-growing companies like Ramp,
Writer, and Harvey save time and resources
while scaling fast with Vanta.
Learn more at vanta.com/darknet.
That's spelled V-A-N-T-A, vanta.com/darknet.
So hackers broke into a company and copied the source code
and managed infosec there for a while.
And currently, too, it was the type of network that was,
you know, in the process of being brought over
to a kind of set standard.
This is Craig.
He helped clean up the intrusion.
So my name is Craig Jones.
I'm the chief security officer of Ontinue.
But several years ago, I was actually the senior director
of information security inside Sophos.
I mean, if you don't know Sophos,
we're a UK-based cybersecurity provider
that has everything from kind of EDR, MDR,
and through into firewall products.
And at the time, they had three different firewall products,
one being Cybro, the other one being a German-based
firewall provider, and the new Sophos firewall product.
So essentially, they were collapsing two products
into one, and the new one being Sophos Firewall.
Yeah, Sophos' main product is their firewall.
This is a network device that will act as a wall
between a protected network and an unprotected one.
Out of the box, nothing is there.
Nothing is allowed to pass.
You have to tell it exactly what you want to allow through,
because the point of a firewall is to stop unwanted traffic
from coming into your network.
And believe me, there's a lot of unwanted traffic
that's always trying to get into our networks.
And in 2014, they bought another company called CyberRome,
which was also making an interesting security product.
That product, you know, we were flattening that product
to make it into something else, you know?
Like CyberRome was very much purchased to be the development house
for the new Sophos firewall product.
You know, there's some super hot developers there.
And it was this newly acquired CyberRome network,
which was the victim of this attack.
Someone had gotten into CyberRome and was looking
for their source code and found it for one of their products,
which Craig and his team had to go clean up that intrusion.
There's some really cool stuff that those actors did.
You know, there was several points where I sat down and thought,
"Damn, these guys really know what they're doing."
You know, I think for me, there was one where they'd
actually attempted to intrude the network
in several different ways, mostly at the same time.
And what was really interesting about it is we could tell
that there were two or three actors working together
in different consoles.
And one of the things they did, which was kind of funny,
actually, was that they'd gotten hold of a secure shell key.
And one had obviously copied it.
And another person was trying to type in the password for it.
And we could tell in the logs that they,
they were mistyping the password, you know?
And, you know, the person who'd obviously taken the key
had obviously tried to relay onto another person.
And they were mistyping this thing.
And it was kind of crazy.
You immediately knew then that this wasn't just like a dude.
You know, this was a serious operation.
The attackers had really unique methods for getting in,
not methods that were publicly known at the time.
Super sneaky and crafty ways to get into a network.
And they got in through multiple ways.
And then when they got in,
they were able to move laterally in really unique ways too.
So unique that the Sophos team had no idea
that stuff was even possible.
It was like exploiting bugs in the way AWS handles identity.
One problem though,
is that they didn't have enough monitoring at first
to know exactly what these hackers saw or took.
They assume because they got access to the repository
with the source code that they took the source code,
but they were unsure.
So they had to enable a lot more logging and monitoring
to fully eradicate them from the cyber realm network.
Andrew wrote,
wrote this attack up because it was so interesting and new
Published it on the Sophos blog, but didn't say who the target was.
Yeah.
So, flash forward two years go by.
It's now 2020.
You know, we now have the team up and running.
I've got a couple of people working with me.
We're publishing a few blogs a week.
And I find out from internal people within the company that there's a security incident.
And the security incident started with a tech support call where someone sent an email to their support technician and said,
Hey, my firewall is showing this URL in the user interface, and I didn't put it there, and I don't know why it's there.
Hmm.
It sounds like a minor problem at the surface.
This firewall had a configuration which showed what IPs are allowed to access it and manage it and configure it.
And a strange URL was showing up in that list of IPs.
It didn't make sense.
It didn't make any sense as to why it was there or why anyone would ever even put it there.
So, Sophos has a firewall called the XG firewall.
At this point, it was just called the XG firewall.
And the firewall has its own operating system.
It's running a version of Linux in it.
It has a UI that's running on the front of it so that you can manage it.
At the same time, someone outside of Sophos submitted a bug into Sophos for this same issue.
I think it was April.
April 21st, they had, well, we actually had an external bug bounty report as a SQLI injection.
And what was kind of weird about it was, you know, I remember the user actually claiming to be from Australia, but they had a Chinese name, you know.
Now, at the time, we didn't have amazing telemetry from any of the Sophos firewalls.
We had kind of base telemetry, which gave you, like, a lot of information.
It was really designed for product managers to understand what features that, you know, users were using.
So they understood where to put their kind of limited resource time into, right?
So we had that, and we had a really good idea of, like, you know, where all of the serial numbers for these devices sat and their IP addresses associated to it.
So it's always kind of interesting to correlate the IP with the intended location of the researcher.
So we got a researcher's device.
It's one that had never been turned on before, which was pretty suspicious.
You know, it had never been registered.
It was a serial number that had just come from a web trial of a VM.
And we found the IP actually related back to Changdao in China.
Okay, odd.
Someone from China with a trial license of the Sophos firewall found this bug and reported it to Sophos?
And Sophos did, in fact, pay the bug?
What was the bounty for this?
It was about $10,000, I think.
Hmm.
Someone got paid a pretty penny for reporting this bug to Sophos at almost the exact same time that they were seeing it being exploited by devices in the wild.
Strange timing.
We called it ASNOROCK.
So the team investigated this bug further.
It was present in the front-end web user interface of the firewall.
To configure this firewall, you can use a browser and access it that way.
Well, the web UI of this firewall had a SQL injection vulnerability in it.
Basically, in one of the form fields of the firewall, like maybe the username field or something,
an attacker could enter in some commands there, which would glitch out the user input handling mechanism of the firewall
and allow the attacker to inject their own commands into the database of the firewall where the configuration sat.
And this was a really bad bug for Sophos to discover.
Their devices are supposed to be blocking hackers from getting into the network, yet it's the vulnerable device which is allowing hackers into it?
This is not good at all.
And they found that, essentially, every firewall that was facing the public internet was affected by this bug.
These firewalls weren't just vulnerable.
They all had been hacked into, exploited.
Someone probably scanned the whole internet looking for these particular Sophos firewalls and then ran some kind of automation script to go infect them all.
We kind of worked out that there were a huge amount of devices.
And I think that's what was affected.
I think in the aimed FBI report that came out about this, I think they mentioned 80,000.
It has a guess that it's probably more, you know?
Hot dog.
80,000 Sophos firewalls hacked into.
But just because someone put a URL in place where it shouldn't be, that's not all that damaging just by itself.
So the team investigated what that URL did, and that's when they started to panic.
The URL would trick them.
It would trigger a GET request in order to update the Sophos firewall itself.
But what was really weird about it is that it was a WGET to a domain called SophosFirewallUpdate.com.
And Sophos didn't own that domain.
So it tried to blend in like it was supposed to be there.
And it fooled many of the people, even at Sophos, who just figured the update domains changed.
But my goodness, this meant suddenly 80,000 firewalls were looking somewhere else for updates and not to Sophos?
And it's kind of strange because we actually monitor all domain registrations.
It's kind of part of our kind of core security, like ops function.
So every single like cert that was registered, every domain that was registered,
we kind of pop up and, you know, anything infringed on Sophos IP, we attempt to pull back, you know?
And it was one that had popped up like a little while ago, but nothing had kind of come of it, you know?
But actually seeing this thing in operation was quite like, quite jarring, you know?
And I don't know if you fully understand what this means.
If a malicious hacker is able to send your firewall software updates, then they can put in whatever they want.
They can give themselves full access to the firewall or they can log all traffic going through it.
They can poke a hole in the firewall and let themselves right into your network.
And then from there, they can just infect your whole network with ransomware.
The thing that is supposed to block unwanted traffic is no longer blocking anything if the attacker wants it that way.
Not only that, Sophos was worried that they had lost capability to update any
of their firewalls properly.
Yeah, so effectively, what they could do, I mean, the truth is anything,
what they really were after was system configuration and passwords.
Now, I've always suspected that this was something that they expected to run
quietly for them to kind of pull that configuration, the passwords quietly,
and then for them to kind of delete any presence they ever had on those firewalls.
And then for them to have a really easy
and simple access campaign.
So the attackers took copies of the configurations from the firewalls and then
passwords from it. This was a pretty darn scary event for the Sophos team to handle.
So it was very much like an incredibly tense situation where
we first had to get a hold of one of these devices.
You know, we set multiple teams up to work out what happened
and to really do some in-depth incident response on this.
We're incredibly lucky, you know, we had the entire arm of like Sophos labs
to help us kind of reverse engineer this stuff.
OK, step one, fix the bug that made these things vulnerable.
And step two is get the bug fix on as many firewalls as soon as possible.
They were able to complete step one pretty quick.
But step two was a little bit more tricky.
If you buy a firewall, whether for your home or a large enterprise,
typically you've got to update it yourself, just like how you have to do your own software updates on your phone
or computer. Sophos firewalls are no different.
The customers are the ones who have to issue updates for this thing.
But to Sophos, this was too critical
of a bug to try to tell 80,000 customers, go update your firewalls,
because I'm just guessing that like less than 50 percent of them would do it in the first month.
There's just not enough time or it's not a high enough priority for them to fix it.
So Sophos decided to do something they've never done before.
They pushed out a hot fix to these
firewalls. A hot fix is like a little software patch that can run in real time.
They can live update all the firewalls remotely with these hot fixes.
It doesn't require the firewall to reboot to be enabled.
And they felt like they had analyzed the attack and figured out exactly how
the threat actors were leveraging their access.
And they closed those loopholes with the hot fix.
This was the first time Sophos ever issued a hot fix.
And it was a hot fix to one of their customers devices.
Now, they had built the facility to do
hot fixes and they had not really used them before this.
So there had been no real reason to do it.
But I think they had built in the capability to do these hot fixes,
anticipating that there might be an opportunity to use it if there was
something that was a real problem. And it was fortunate that they had rolled this
out in the previous firmware update that, you know, just before this attack
had taken place.
Yeah, I think this is a really big deal.
Like, it makes me wonder if there's language in the small print of the terms
of service that says Sophos reserves the right to make configuration changes to
your firewall or or updated whenever they want.
I think that's what's important as well.
It's like this isn't something that's just kind of done and it's not something
that's done willy nilly, you know, and you're right.
I mean, it does feel kind of offensive.
Someone coming in and tampering with my stuff, you know.
But effectively, it's written into the EULA, like the End User License Agreement.
And candidly, you kind of need this.
And I think that's where a lot of firewall providers actually fail, is the fact that they rely
on end users to patch everything and and candidly so many firewalls that just bought and they never
updated you know gosh i really don't know where i stand on this i was a firewall admin for my
previous employer for 10 years those cisco firewalls were my babies i knew everything
about them i would review every single change that ever took place on them and i don't think
i would like it if cisco just decided to patch them one day without my consent like somewhere
in hospitals that were mission critical and some hadn't been patched for years because they were so
finicky and any change to them would just make them wig out and crash and when i had to update
them i wouldn't do them all at once in one big swoop i'd do them one at a time and hold their
hand and make sure that nothing broke after the upgrade and everything came back up as expected
so if a security vendor just slapped a hot fix on all my firewalls that i was in charge of
i would freak out what we did not get approval for this change we aren't in a maintenance window
we don't even know what changes you made to the firewall or what's happening how can you just come
into our devices and make changes without us knowing i would be upset like i wondered the
sofos team get approval from their lawyers before issuing a hot fix to their customers like this is
this even legal yeah i mean that's that's a great question i i was not privy to those discussions
but uh but there were i'm sure there were discussions like that about you know what is
our legal liability what are we allowed to do and not do remotely on these devices um i believe
ultimately the decision was made and i'm not sure if there were lawyers consulted on this or not but
made a lot of sense that the the harm of allowing the firewalls to basically try to ransomware the
inside of networks was probably greater than the risk of somebody complaining that uh oh you made
a change to my firewall without telling me first so they just went ahead and did it
yeah i mean i think not only that but it's like this idea that the vendor can come in and change
my device in any way it's not just like crash logs that are being sent to it it's wow what else can
you do if you could put a hot fix in can you see the password can you see the connections can you
see can you come in and do other work can you uh update to different firmware that has malware on
something like could you do things that you know and and you know you you start your mind starts
going like could you do things that the nsa wants you to do and go and spy on this customer or
something like that right and so when you're a firewall admin you're like no i have to make
sure that this is no other you person in the planet can access this but me and other people
on my team because you can't risk some like a backdoor but it's basically a backdoor that you
had yeah that's entirely accurate and you're not wrong um and these are these are devices that are
typically placed in a in a position in the network where they act as the barrier between
the outside and the inside worlds of of your the networks and i and i recognize that that is a risk
um however and it is also worth noting that this is exactly what the bad guys were doing
at this moment they were installing malware inside the firewall so how do you fix that
i could just imagine the headlines at this point and just i i don't my question is did any bad news
come out to be like sofos found vulnerable tens of thousands of customers impacted um huge
vulnerability hacker has complete control over their firewalls patch immediately like that could
make the stock tumble that could you know really hurt business uh yeah i mean it could and that
was one of the reasons that i was brought in basically on day zero of this happening um
the company realized that they had a public potential public relations nightmare on their
hands and they needed to communicate uh as as openly and as forthrightly as possible everything
that they knew and everything that they were doing to fix it um and you know credit goes to
the people you know in leadership at the company who decided that uh you know possibly against the
you know conventional wisdom at the time that they were going to go public with with everything we
knew about this attack
um it was not a common thing at that time but uh as i said you know i've worked for a long time
doing this kind of in this kind of role where i do investigations and then you know publish about
them to the public to warn people about bad things that are happening on the internet and it's been
my experience that the the more uh information that you get out the the better protected people
transparent, benefits everyone. It helps the customers who are affected. It also warns the
public that like, hey, this is something that you need to be aware of in the future. And it might
also put the threat actors on notice that, hey, we're watching you and we're taking action to
stop you. As the Sophos team investigated this more, they learned that whoever did this attack
had to have really in-depth knowledge of Sophos firewalls. Like there's no way they should have
discovered this bug unless they had access to the source code, which wasn't publicly available. And
that's when the pieces started clicking into place. The part of this firewall that was vulnerable
was code from the CyberRome firewall that was moved over to the Sophos firewall.
And two years before this, as you know, there was an attack on CyberRome. And what server did
the attackers get access to?
The one with the source code for their firewall. So they started to think, holy crap, this is a very
serious threat actor who's been attacking us for years. They spent tons of effort getting into
CyberRome's network to steal the source code only to study it for bugs and then launch a massive
attack on our Sophos firewalls. Whoa, what do we even do with this information? To think your
products are the target for a major cybersecurity campaign like this? This is starting to
smell like a nation state actor is behind this. Who else has that much time and resources? And what
the heck was the deal with someone from China submitting this bug the exact same time that
Sophos discovered this? Very strange. One of the things that we've been kind of working on even
before this situation was, you know, pulling in our telemetry or firewall telemetry, the kind of
basic telemetry I was talking about earlier into Splunk. And I remember talking to Mark, who was
just this amazing Splunk engineer on my team.
I said, well, can we go back on that data? Like, can we find out, like, when this first started?
Because I couldn't quite work out the exact moment in time, or the first firewall that was hit by
this, this Asnarok attack. And then I went back, how far does that data go back? And then Mark said,
well, actually, I think I've got like three months worth. So we kind of rolled this thing back three
months. And there's one single device.
That had been hit like a month or so beforehand, like sometime in February, if my memory serves me
right. And it was just really strange. So it was kind of registered to like a Chinese 163 address,
and it sat again in Chengdu.
Chengdu, China again? That's where the person who submitted the bug was from. So they took this
firewall. And again, this one was running a trial license, which was actually just a software based
firewall running in a virtual machine. And it's a virtual machine because Sophos isn't allowed to
sell their firewalls to China due to export controls. So really, nobody in China should
even have a Sophos firewall. Their suspicion was that the attackers were using this virtual
firewall to practice their attacks against, develop them, and then unleash them against the
world. Because Sophos has the ability to run in a virtual machine with trial licenses, they can just
spin one up real quick, try attacks on it. If they mess up the firewall, they can just reboot it,
take it down. And then they can just run it. And then they can just
take it down and bring a fresh one up in minutes.
We found this trial license, and they were can also see to 163 address and a moniker that we
called G Big Mao.
Okay, interesting. They looked up who registered that trial license, and this gave them an IP
address, a username and an email address. And the username was G Big Mao. So now you pivot on that
name. What other Sophos products has G Big Mao downloaded?
We kind of pivoted on him. We found that he actually started to experiment with this,
with this database or SQL injection like our mother. So go on, we can find then looking at
his IP address. Again, we had phenomenal telemetry here, that he was looking at different knowledge
base articles around our kind of previous CVEs issues. He was looking through our forum system
to look at maybe other potential.
Issues or places that he can maybe pivot and work on.
Then they took a look at his email address and wondered, has this email address been used anywhere
else in the world? So they do some OSINT investigation to see if this email is known anywhere
else.
And we find that he was an actual firewall researcher. And he published like a number of
different like vulnerabilities. We could see him on kind of Linux boards, you know, publishing
various different router vulnerabilities.
Up until about 2018. And then he went silent. You know, he'd been really, really busy up until like 2018. Now, we kind of found out that he was working for
company called Xizhuan Silence Information Security Technology, mostly because doing some
extra OSINT, we found that his username appeared in many like Chinese hacking groups and lots of
CTFs, so like capture the flag type events, where he'd been registered towards this company as well.
So we found kind of corroborating evidence from a couple of different places that this was the same
guy in the same company, you know, again, located in Chengdao in China. So we found a really clear
picture of who this person was. Now his external OPSEC was pretty good, you know, like you would
not have been able to find him that easily. But because we could see the internal telemetry and
get the license information, kind of connect the dots, we could actually pin these devices to him
and his usage. But for Xizhuan Silence Information Security Technology, we found that Xizhuan Silence
Information Technology was very good. What we had to do at that point was find out more about
these devices that were being used for research. We found that from the limited telemetry that we'd
started to gather with the first hotfix, but what we realized is we actually needed more,
like we really needed more detail, faster detail to like a greater depth
to understand what these guys were doing. So we developed a kernel implant in-house.
A kernel implant. That's a nice way to say it. I guess when the good guys make it,
it's called an implant. But if the bad guys were to make it, it would just be called malware.
But essentially, a kernel implant is a hidden piece of software that they developed to sneak
onto their firewalls to covertly and sneakily spy on what the firewall is doing.
Yeah, so there's a lot of interest within the company. Well, we know that there's these
firewalls that have been registered to the Xizhuan Silence Information Security Technology.
So we know that there's a lot of interest within the company. Well, we know that there's a lot of interest within the company.
count of the number of firewalls that are being used in these places. And we could see from some
of the log telemetry that the threat actors are running commands that are testing how these
exploits are going to work. But we don't have the exploit code itself. So the security team decides
they're going to build something that they just call the implant, or sometimes they call it the
kernel implant. And it's a small ELF binary that gets distributed only to the machines that they
are specifically interested in taking a closer look at. So these machines that they believe are
being operated by threat actors, where they're doing these commands that are way outside of the
boundaries of normal firewall behavior. And these things are capable of doing more than just sending
commands to the machine. They're capable of doing more than just sending commands to the machine.
They're capable of
sending commands to the machine. They're
to just quite incredible engineers.
They built this kernel implant
that allowed us to basically move Sophos Firewalls
from like a normal update path
to like a specific update wing.
And we would then deploy this specialist kernel implant
in a normal update.
And you just wouldn't see it.
But what it allowed us to do is like grab anything
being needed from the device.
So for example, things like files,
if there were entry updates,
it would kind of record anything
that was kind of written to specific writable directories.
And it would start to give us a really good idea
of what they're doing, what they're writing,
why they were doing it.
But some of the really cool things
that we actually got from it were quite unexpected.
So for example, we started to pick up
on the devices around the firewall.
So we'd, you know, capture,
all the MAC addresses of devices connecting to this firewall.
We'd also capture MAC addresses of things
that also sat in the network alongside the firewall.
And then we suddenly realized that actually this is huge.
This isn't just like Sophos Firewalls.
We've seen other vendors' devices on the same subnet
alongside the Sophos Firewall.
You know, they were looking at all sorts of devices.
You can probably pull from the top of your head,
thinking about things that have been attacked in the past.
You can probably pull from the top of your head, thinking about things that had been attacked in the past.
And this is now tugging at me in new ways.
If every firewall vendor is getting hit with the same type of attack, and Sophos is the only one being transparent about what they're seeing and what they're doing to mitigate this, then yeah, I give them a lot of credit for that.
Here's the test, I think, for whether your company is evil or not.
First, it has to be transparent to its customers.
Let them know exactly what kind of configuration changes, updates, or spying, or data collection you're doing on your customer's device.
Let them know exactly what kind of configuration changes, updates, or data collection you're doing on your customer's device.
And in what circumstances, and what's that you're being used for?
And second, be proud of whatever it is you're doing around that.
If you're a company which is making changes to the customer's products, but then not telling them, and secretly adding spyware, but making it so top secret that not many people on your team even know it exists, then I think you might be evil.
If you're afraid to let the public know, then you might be evil.
public know exactly how you operate, because you think it's going to look bad on you, or maybe
because you think it's not even right, then either stop doing it or go public with it. And Sophos
came to the conclusion that while this is not an ideal situation, this threat is novel and
sophisticated in ways nobody's ever seen before. And not only that, whoever was doing this,
they're being unethical themselves. So Sophos had to deploy a novel and sophisticated approach to
defending their device. And while it's not pretty, at least they came out and told us about it
through Andrew's blog posts. And they're basically saying, hey, we're in the middle of a nasty street
fight here, and the gloves are off until we can neutralize this threat. And again, I give them a
lot of credit for that. Nice job. So at the same time, they were developing this implant to eavesdrop
on the hackers. They were also in the process of studying those domains which were found in the
exploited firewalls. The hackers pointed all the firewalls at two domains to get updates from,
which were not owned by Sophos. Yeah, well, there was SophosFirewallUpdate.com and
SophosProductUpdate.com, which were registered at different registrars and hosted in different IP
spaces. But because they both had Sophos in the name and they were part of this attack,
Sophos went to ICANN and did the domain name seizure process on those domains so that they
could pull those down and start to, they wanted to sinkhole the domains and see what was connecting
into them. How do you seize a domain? Well, with lawyers and money. And, you know, it's a really
serious thing, you know, like attending court in Delaware, I think it was, you know, remotely,
because at the time, don't forget that this is the thick of COVID. Jeez, that's another thing that's
taken over someone else's domain. If you can prove that you're the one who's the rightful owner of it
or should be owning it. But they gave enough reasons to the courts, who then demanded that
the domain registrar give Sophos control of the hackers' malicious domains.
The server used by the threat actor actually sat in the Netherlands, and it was one of these
bulletproof, like, hosting providers. So we were super lucky that, you know, through the NCSC,
in the Netherlands, they were kind of an intermediary with the kind of Dutch National
High Tech Crime Unit. And once we kind of realized how this was panning out, the Dutch National High
Tech Crime Unit just jumped on this. And they managed to get hold of this C2 server. So the
actual physical Linux box. I guess it wasn't bulletproof then, huh?
Well, yeah, this is the thing, you know. So they managed to grab hold of it. And, I mean, we were
super keen on it. We were super keen on it. And, you know, we were super keen on it. We were super keen to--
How do you even--so how does that happen? You convince the Dutch authorities. So you're just a
company in the UK. You're just like, "Hey, we make this product." You can't just call up the Dutch
police and say, "Go get that server. We need it." And then they're like, "We're on it."
Well, yeah, I mean, you'd think. But then, you know, luckily or unluckily for us, there were a
couple of Dutch customers affected, you know, by this attack. So that allowed us to be able to
register a crime and then get assistance.
And we did this globally, you know. We really used all of the resources available to us.
So, you know, this obviously took time. You know, I think right now this is like three or four days
after the attack. But the NCSC in the Netherlands were incredible. And the Dutch guys there were
just super helpful. I mean, we wanted a copy of that threat actor device. Like, I wanted to see
that Linux box and understand what they've done.
I mean, obviously, it was evidence now. It wasn't owned by us. So, we couldn't get a snapshot of it, for example.
But they allowed us to basically, you know, work with them and analyze the box live on a screen share so we could actually understand the scale of what had happened, you know.
And we'd seen the threat actor scripts for scanning the devices, the outputs that they'd taken from the firewall, you know, how they'd
set this thing up, you know. Kind of Chinese characters and notes and things throughout the device.
What was actually surprising was that everything was kind of set up manually on the C2 server.
I kind of expected them to deliver the C2 server with some sort of kind of dev ops pizzazz.
But it was just basic. You know, it was like a Linux box and someone had copied subscripts to it, you know.
But they were amazing. I mean, the NCSC in the Netherlands just gave us so
much help and really helped us focus what we, you know, where we needed to look and the kind of scope and scale of all of this.
At the same time, they got control of the domains used by the hackers and sent all the traffic they were getting to a sinkhole and logged it all.
It's just fascinating to think that, like, I don't know, a Netgear, a Linksys, you know, some other commercial product was checking into sofasfirewallupdate.com and kind of, it almost screams of,
like, well, you know, we could be bothered to register this domain for sofos.
We're not going to bother to register it for these other companies.
Like, we already got the domain.
We're just going to keep using it for these other things.
I couldn't find a single article by Linksys mentioning any of this.
Nothing at all.
Netgear put out an advisory saying a Chinese threat actor is attacking their products.
However, they say they are not aware of any Netgear devices being exploited out
in the wild, which if they don't have any telemetry from their customers' products, then, yeah, of course, they're not going to know if any devices are being exploited.
And that's what's challenging me here.
Should the firewall vendor be collecting logs off its customers' devices in order to better understand what devices are actively being exploited?
Or should that be the responsibility of the customer?
In many organizations, they have their own security logs and even a team to monitor those logs to look for threats, but things like Netgear and
Linksys are typically home devices, and it's very rare for people in their own homes to be monitoring their logs looking for threats.
I looked it up.
Netgear actually does quite a lot of analytic collection from their customers' devices.
They collect IP addresses, geolocation, how often you use the firewall, what you use the hardware for, what channels your Wi-Fi is set to, and what devices are connected to it.
It's surprising with all that analytics collected that they didn't spot a single device being exploited
by these threat actors.
And this is what frustrates me.
When my home router is sending all kinds of logs to another company, like, what devices are connected to my router?
Really?
I hate that.
I want the devices in my home to be private and not sending tons of data to somewhere without me even knowing.
Because if Netgear has that data, then it's likely a lot of other people have it, too.
But then they also registered for the kill switch, they registered Ragnarok from Asgard, right?
And Ragnarok,
of course, is the Norse mythology end of world myth.
And it was fascinating that that was how they, you know, used that nomenclature and that language behind it.
Because by this point, we already had some folks who were using Marvel characters, superhero names in their user accounts that they were, you know, that they were using for downloading these firewalls.
So we had a guy who used the handle of T. Stark, who was involved
in some of the exploit development and had registered a bunch of these virtual firewalls.
And now we're seeing, you know, this is the timeframe when the TV series Loki came out and when the Thor Ragnarok movie had come out as well.
And it's just fascinating to imagine that these guys who were doing this stuff saw themselves as some kind of, you know, superheroes, or maybe they just, like, put themselves in the shoes of, like, that maybe they're just, you know, maybe they're, like,
up there with gods and that they can, you know, engage in, you know, a hammer that can throw lightning from a distance at an enemy.
Just fascinating to think about.
So this is why Sophos called this particular exploit Asnarok, a combination of the words Asgard and Ragnarok.
And all these efforts on their side paid off.
The implant gave them incredible insight into how these attackers were developing their exploits and were able to write fixes for the next exploits before the attackers could even launch them, which is incredible.
To be in the hacker's machine watching them in order to be one step ahead of them, phew, good job, Sophos.
This looks to be a pretty hairy threat actor that you're dealing with.
But little did everyone know, that was just round one.
We're going to take a quick ad break, but stay with us because round two gets even hairier.
This episode is sponsored by SpyCloud, everyday stolen identity data like credentials, session cookies, PII, and more.
Flows through criminal underground markets, most companies don't know what's been exposed until it's too late.
For the last decade, SpyCloud has existed for one reason, to disrupt cybercrime and end criminals' ability to profit from stolen data.
That mission has never been more urgent.
SpyCloud's latest idea has been to recapture darknet data from successful phishes, infostealer malware, combo lists, and breachers to put it to good use.
They transform it into automated identity threat protection using advanced analytics,
and AI to protect workforce consumers and supplier identities from authentic
syndication bypass, session hijacking,
account takeover, ransomware, and fraud.
Don't wait to become the headline.
Find out what criminals already know about your organization.
Get your free Darknet exposure report
at spycloud.com slash darknetdiaries.
That's spycloud.com slash darknetdiaries.
Yeah, so that kind of wraps up round one.
You identified, you fixed, you cleared,
you found all the ones that didn't get fixed,
you found that fixed those,
and took down the whole infrastructure
that was doing it, done.
That's patched like permanently, 100%.
There's nothing that no customer has
that's not patched.
We're good.
Yeah.
So everything I've just described to you
happened over four days.
Which is just, yeah, when you think about it,
I mean, it's insane.
It's basically one of the largest,
widest incident response operations on earth.
And we did it in four days.
Wow.
And I still think about it now.
I mean, it's like a crazy situation.
But we were lucky with an amazing team.
It was, you know, things aligned, you know.
Amazing.
That's got to be one of those four days
that is permanently in your head,
like a light bulb experience of work.
Like a lot of people are being on the show
and I say, tell me about the worst day of your life.
And would you say that that's probably it?
I wouldn't say it was the worst day.
I would probably say it was,
it was an experience, right?
I mean, I remember thinking at the time,
oh my God, this just can't get any worse, you know.
And every time we'd kind of look at this,
there'd be something else or, you know,
I remember as these devices were checking into telemetry,
we just see the number of affected devices grow.
And I remember feeling like just this gut-wrenching feeling
of like, oh.
Within about, I don't know, six to eight weeks
after the hotfixes were rolled out,
the threat actors had figured out what the hotfix did
to make it impossible for the Ragnarok attack to work.
And they had done a workaround.
They had just, you know, bounced their attack around
the thing that the hotfix was able to, you know,
in a very rapid way,
kludge together to make it not work.
They kludged together something that got around that hotfix.
And wham, round two officially begins.
More Sophos firewalls are getting hit with a brand new,
new vulnerability.
One that Sophos had no idea was even possible.
But Sophos was ready.
They even developed a specialized team just to handle this.
Xops.
So Xops jumped on it.
They saw what the vulnerability was.
They wrote a fix for it and started immediately trying
to patch the firewalls.
The team starts to realize, oh, we need to give these things names
because if we're going to be having these attacks happen
in, you know, sequence in short order, to just keep straight,
we need to come up with names.
So they,
they decide to use the names of locations around the Pacific
rim as the code names for these internal attacks.
So they,
they give this attack a nickname Baja.
It doesn't have anything to do with Mexico.
It's just,
they just decided that they want to talk about it in the sense
of, you know,
it's on the Pacific rim,
which is a region of the world where volcanoes and earthquakes
happen, right?
So it's,
it's a place of turmoil.
So internally Sophos realized this attack is a big,
bigger than a single attack.
This attack is linked to multiple attack campaigns against
their product.
So they called this whole series of incidents,
the Pacific rim campaign.
So what the threat actors figured out when they were doing
this the development of this Baja attack is they watched
Sophos and they watched how the hotfix mechanism worked.
And they learned how to develop a new exploit,
but also,
they started to develop technology and technique to get around hotfixes.
So they would,
they figured out how hotfixes were being deployed on firewalls,
and they were slowly starting to turn off features inside the
firewall that allow the hotfixes to launch and run and do
their fixing that this time they're putting just regular old web
shelves on the firewalls.
A shell is like CLI access to a computer.
A web shell is having,
having remote CLI access to a computer over the internet.
And what the threat actors did this round was simply give themselves
remote access to as many Sophos firewalls as they could.
And this also removed the need for the attackers to use command and
control service because they could just log in directly to the firewall
whenever they wanted and do whatever they wanted to it,
which again is a huge problem.
You should not allow attackers to enter your firewall on the internet.
This is like the security guard of the building suddenly being remote
controlled by the bad guys in June.
I mean,
we,
we've seen this this attack happened.
Obviously,
you know,
it was an Apache module issue and it was changed was like a
local privilege escalation.
So it's basically,
again,
any device that had a one facing web portal could be affected,
which was a lot of devices.
The threat actors set up these web shells where they just
needed a username and a password to log in.
And so the Sophos team tried to crack that password,
but they couldn't for some reason.
Actually,
I think we unsuccessfully tried to crack the hash of the password,
but I think eventually we find out that the actual password is was Gucci.
Um,
no,
which was,
I mean,
we can't come across this a while later because it was,
it seemed to be a common password for Chinese three actors.
He used the word Gucci.
No,
I have no idea why you'll find,
I think at the time was about 175,
200 devices.
Um,
that were affected.
Okay.
So one thing you want to do in your investigation is to try to
see if there's a commonality of what firewalls are being exploited like this.
And that might give you a clue as to what might be
next or who's behind this.
So they start looking to see where these firewalls exists in the world and
for which customers.
Yeah.
So,
so this one was very much targeted.
You know,
the first attack was very much a,
a,
a spreen pre type attack.
You know,
this was specific devices around the kind of Asia Pacific.
Area. I think,
you know,
like Taiwan,
Pakistan,
places like,
um,
Philippines,
you know,
very much targeted,
completely different to the first attack.
And,
you know,
we,
we kind of find that,
you know,
this one had,
had delivered payloads that had been used in kind of earlier attacks as well.
So again,
you know,
two Linux shell scripts.
So we were able to kind of connect it back to a,
a specific actor.
You know,
we,
we obviously seen these specific files and hashes,
um,
on on the device that we've been tracking and then eventually we see it being used.
Now what was kind of interesting about the way that they would develop these is that we can see them starting to work now,
obviously to be working to Chinese hours,
they work nine to five and you know would see them with amazing opsec externally.
But the opsec they had on the box was atrocious.
So they would be,
for example,
um,
working with crash,
dumps.
Um,
and you could set up the software firewall that if you ever had a kernel crash or a crash of any sort,
it would email you the crash logs to your email address.
Well,
these guys would use their personal email addresses.
So imagine the actual firewalls registered to a completely anonymous person.
And then we have linked email addresses and Gmail addresses,
um,
inside the firewall telemetry because I guess it was probably quickest and easiest for them to grab that stuff from their personal mail,
you know?
And it was super easy for us to like OSN exactly who these people were.
They start looking back in time at the telemetry that they collected and they discover that this was another bug that someone had submitted a bug bounty for and gotten payout on and here it is being used in the wild,
like just days after the payout happens.
So this is starting to get to be a pattern.
And,
the,
the attacks are,
you know,
widespread.
People are getting noticed about it.
So I get called in and have to,
you know,
decode how the whole attack works and do another flowchart similar to what we did with ASNOROCK to do the Baja attack.
So these two names keep showing up again in their analysis of these attacks,
which are G.
Big Mao and T.
Stark.
These are the people who registered for trial licenses of Sophos firewalls.
They were in China.
And the malware would show up on their device first,
which would indicate this is where all this is originating from.
Well,
you know,
one of the,
one of the things that we can do.
So you've got this telemetry tool that you can,
you can do basically wide scale threat hunting within the firewalls themselves.
And so you can do things like,
okay,
well,
we recovered a piece of malware off of the very first machine that was that belonged to a customer.
Um,
let's see where else this malware exists on,
you know,
the,
you know,
the universe of firewalls that are out there.
And that was how they found T.
Stark.
So T.
Stark's firewall was the first one where they,
uh,
they found a copy of the,
not just the same malware,
but like the binary identical,
like the actual same file,
uh,
on this guy's firewall.
And he had been there for two months.
So he'd been experimenting with this piece of malware,
uh,
while the Azeroth attack was happening,
he was,
he was basically planning the next one,
like in the middle of us dealing with the aftermath.
they were already developing the exploit
and building out the payload for that attack.
And then the other thing that was really interesting
was that we found a bunch of other stuff
on this T-Star guy's firewall.
His firewall had a bunch of malware on it
that was designed to run on the Mac
and on iOS, on iPads and iPhones.
And there is no conceivable reason
why there would be like a Mac executable
on a inside of a Sophos firewall.
It just, there's no reason for that.
So that was an interesting find.
And we didn't really understand
what that was being used for,
why that was there until much later.
Yeah, what was that?
So this all happened in June.
Starting around August, September,
Sophos had started to communicate
with other companies in the field,
some of whom did forensic analysis
for post-attack analysis for their customers.
And one of these companies is called Vilexity.
And Vilexity reached out to Sophos
because they had a customer with Sophos firewalls
and they were called in to do the investigation
on the Baja attack.
And they had also discovered Mac OS
and iOS software in their firewall.
And Vilexity came to Sophos and said,
hey guys, why is this here?
We had no idea.
But it turned out,
so Vilexity,
Vilexity had figured out
that the threat actors
who were dropping these pieces of software
on the Sophos firewalls
that they were investigating,
that the owners of those firewalls
were operating a charity
that supports the Uyghur diaspora.
And the Uyghurs are an oppressed minority in China.
They believe in Islam.
And they practice their faith.
But they are strongly discouraged from doing so.
And they've been put in prison camps.
And, you know, the story of the Uyghurs
is outside of the scope of this podcast.
But the point is,
is that there's really only one organization
that actually cares about these two groups of people,
you know, about surveillance of these two groups of people.
And that is the government of China.
During that time,
they kept a close eye on the activity,
of G. Big Mao's firewall.
And they would see,
it would just get infected with a new vulnerability,
which was like the fourth zero-day vulnerability
on the Sophos firewalls.
Zero-day vulnerabilities are ones
that Sophos doesn't even know exist.
They've had zero days to fix this, basically.
And for me, this is the point
where I suddenly see the scale of all this.
The first attack was scary already.
But four zero-days on a security device
discovered and leveraged by the same threat actor?
That is a lot of time and resources
put into finding ways
to attack Sophos products.
This isn't just a group of kids
or even some kind of cybercriminal
which is focused on making money.
When someone can spend this much resources and time
focusing on getting into a very specific thing
and spend years doing it,
that's typically a nation-state behind it.
The skills and patience were so impressive here,
which meant Sophos had a lot of work ahead of them
to fix this.
Absolutely.
You can imagine, like, the amount of work
that this spins up,
and the way that it kind of balloons out of control.
As you discover that more and more pieces
of the open-source code base that you're using
are being exploited in different ways.
Yeah, who has time for all of that?
If all you're doing is just fixing these patches,
that could be a full-time job.
But you're also supposed to be building out a product
that has new features and response to customers
requests and all other things.
So, yeah, at a certain point, it just becomes oppressive.
Like, the amount of patching that you have to do
and the analysis involved in that
and, you know, fixing the firewall
takes just as much QA.
You know, it takes time to build things that don't break.
And these are critical.
I don't want to say they're critical infrastructure,
but they're protecting critical infrastructure.
Yeah, I mean, in reality, you know,
it's clear at that point that, you know,
the softest firewall itself needed some hardening.
I mean, that part is fairly clear.
There was an internal mission going on
where dev resources may pivot to try and harden
certain elements of the operating system
and web portal to really help us.
That web portal.
I tell you, man, the more ports you have open,
the more vulnerable you are.
And if you have a web portal,
you're going to have a million different ways
to mess with that thing.
You are.
When I was a firewall admin,
I was very adamant about zero exposure to the internet.
No SSH port, no web portal, nothing is allowed.
The internet should be able to access this firewall.
If you want to get to this firewall,
you have to come at it from the inside.
Exactly.
And I wish every firewall admin acted like you, Jack.
But in reality, we have people
who just put the firewall on the internet
and they put the web portal out there.
There was some legitimacy around putting your web portal
out there because you had the admin portal,
which is separate to the web portal.
And the web portal was where users picked up SSL profiles
and, you know, things like that.
I mean, it is wild to think that someone
or some team out there is working feverishly
to find vulnerabilities in your product
and then to have an implant on their firewall
so you can watch them develop their exploits.
And the threat actor had no idea
there was an implant on there
watching what they were doing.
The Sophos team did a really good job at hiding it.
It would be really hard for them to notice.
It was really well hidden, you know.
So, you know, we did start to get some really good telemetry
and start to know these guys.
And honestly, we were really obsessed with it.
It was almost like obsession ops.
We would just wait for this telemetry to come in
and then we would be all over it.
You know, we'd start to dissect what they were doing,
how they were working.
You know, if they'd had any new IP addresses,
we'd start to OS into it
and we'd start to build a picture of who these people were.
There were multiple threat actors
that we were watching at any one time.
And, you know, it's kind of funny
because, like, you know, I often think that, you know,
external threat intelligence is very much like,
almost like astrology, infosec astrology, you know,
where people are kind of connecting a technique
to a specific threat actor group.
Dude, we had names.
We could tie them to companies, you know.
You know, and then we could tie it to threat actor group attribution.
You know, it was a really weird situation we were in.
We had visibility that was just unreal.
I remember, like, at one point,
we seen one of the actors searching for a flat.
So we started to work out that, you know,
he was looking for a flat.
Like, he was a normal dude.
You know, he's going about his everyday life,
probably sitting there bored in the lab,
you know, having run the same test 10 times
and thinking, you know,
I'd really need to sort my housing situation, you know.
And we're there, like, building this picture of his life.
And, honestly, we were obsessed by it.
It really became, like, obsession ops.
Yeah, because since Craig had control of the firewall
in that guy's lab,
he could essentially see all the traffic going through it,
which gave him a unique look into this person's life.
And with these new insights
and closely watching everything that was going on,
the Sophos team were able to quickly create fixes
for the vulnerabilities to minimize the impact
as best as they could.
So with all these vulnerabilities fixed,
round two of this battle came to a close.
Sophos had a lot of bruises,
but I think they won the battle.
Yeah, that's it for round two.
But, you know, there's several part that is kind of useful.
Number one, round two really validated our use of telemetry.
It was the first time that we'd really used our implant.
The other aspect to this as well is
we've become really adept at finding these threat actor devices.
So we started to work out that, obviously,
we'd identified this actor called G. Big Mouth.
But all in all, we were dealing with about seven different actors
that we could see.
You know, some of them were doing the same thing,
but in different locations.
So we kind of worked out quite quickly
that they're working for individual Chinese defense contractors.
Because when you think about like a government department,
they're not going to duplicate the same work
because effectively it's all the same people working.
Where a defense contractor, everything is valuable to them.
If they're the first to an exploit, that's super valuable.
So what we found then is we found these multiple companies.
And one of the simplest ways we actually find it, funnily enough,
and this sounds so basic,
is that we would look at devices
that would be continually going up and down firmware versions.
And these threat actor devices would constantly like
put the new lace firmware on, roll it back,
new firmware, roll it back.
And they do this like, I don't know, maybe five or six times a day.
Whereas normal firewall operation, it's like it's new firmware and it's left.
And then in a month, it gets new firmware and then it's left.
So these things just stood out like a sore thumb.
So it suddenly became really easy to find these threat actors, you know?
The more telemetry we had, the easier it got, you know?
And we started to really build a wide assortment of threat actors in China,
the locations they had.
And of course, you know, they're honestly piss poor opsec that they had on the device.
the device itself just allowed us to start building up really quite wide
profiles on them and over this period we would start to like really get an idea of how they were
targeting things and it was very much like seeing them do something build an attack know that this
was coming and having to wait for it to be deployed you know I mean if we went and pre-patched the
devices continually they would have noticed they would know that the game was up you know so we
kind of waited to understand what was happening would wait for the first indication of deployment
of whatever they were doing I kind of run and patch it almost immediately you know so we had
like probably one of the craziest uh like forward-going threat intelligence well that's
crazy threat intelligence is simply the understanding of what threats you will face
or have faced this is why I think it's really great having records of all attacks that your
company has ever seen because it's incredibly valuable at helping you defend against
future attacks but in Sophos's case they knew exactly what threat was coming next and were a
hundred percent prepared for it the moment it would be seen that's really slick that's threat
intelligence that's on a whole new level but even after two huge rounds of attacks against Sophos
firewalls and discovering four zero-day exploits on them the war wasn't over the threat actors
continued to develop more and more exploits for Sophos firewalls yeah over time the threat actors
were increasingly they were targeting the game they were targeting the game they were targeting
specific organizations or specific groups uh they you know they had identified who all of the
customers were in those early attacks because they they smacked all of the firewalls at once
and grabbed some data oh my gosh I didn't even think of that so if we back up and look at the
way all this has progressed first they hacked into cyber Rome only to get the source code for
Sophos firewalls which gave them inside information to basically bug hunt then they infected 80 000 so
Sophos firewalls with malware taking all their configurations and information about the firewall
itself and then combed through that looking to see what targets are interesting to them
and now they're being super precise about who they're hitting this campaign keeps evolving
from 2021 onwards it really pivoted towards a very sharp focus to discriminant attacks
you know really highly targeted hands-on keyboard attacks um against like specific entities so for
example government agencies critical infrastructure research and development organizations health care
providers everything from kind of retail through to military even finance you know and again all
focused in the APAC region geez what a nightmare I cannot imagine all these places getting hacked
into through my security device all these companies bought Sophos firewalls to protect
themselves and it was that very firewall which allowed Chinese hackers in ah
at some point did you reach out to some of these victims to say hey I think Chinese government is attacking you
so so that's one thing we did really extensively um well two things one is we'd reach out to the
customer um and again it was this was part of our philosophy of making sure that you know there was
no further damage or no no hurt um and as well we we would reach out to either the localized law enforcement or if we had
uh ties to the local you know cert or ncse or or whoever the the local cyber authority was now in
the UK we had some amazing connections in the ncse uh and they would help us facilitate these these
connections out to to all sorts of certs and bodies and you know they were incredibly supportive of us
yeah I mean what's that call like to call up a government a foreign government uh
I know you're just talking to the sysadmin there but still like hey uh you guys are getting hacked
it's it's pretty strange you know and not only that when we sit there you know obviously through
translation very often explaining what we've seen and what happened and who we attribute it to
it's a very strange experience you know also not as strange as calling up another firewall provider
telling them that their box is being tooled over by a Chinese threat actor and then ask us well how do you know
and not really being able to tell them how we know and why we know but we definitively know
um that's a bit of a weird experience also at some point cyber roam gets hacked into again
well it turns out that the cyber roam code is the predecessor to the xg firewall code so cyber
was the company that surface bought and their product became the xg firewall so when back in
2018 we're talking about how the xg firewall code was the predecessor to the xg firewall code so
the threat actors had stolen the source code you know they were using some of that still to find
additional vulnerabilities and they found a vulnerability at this point cyber roam and the
xg firewall were were in parallel operating but cyber roam was about to be phased out it was about
to be end of life and the threat actors found a vulnerability that allowed them to create an
admin level account on the box with just a sql injection query that that was pre-authentication
so they could just they could just hit the the
sql server that was running on the firewall from the outside and run a command that was able to get
it to add a user with admin access and then they could log in on any cyber room firewall or you
know that they wanted to with that credential uh and there was no easy fix for it and because the
product was close to end of life so if it's just decided to rush it to end of life and get
everybody who was running a cyber roam firewall to upgrade to the latest xg and
put that one to bed because it was it was the point where if we had to start you know tracking
attack against cyber room and xg firewalls that would have taken the entire like all of the entire
team's resources all the time at a certain point it just made better sense to end of life the product
early it does make me think though if they were trying to get into cyber room to get source code
uh they were probably trying to get into sophos's network as well trying to get source code
i mean yeah i i that's an interesting thing to hypothesize about but i have no idea about that
you should say no the sophos firewalls are so good that they're blocked those guys don't worry
well i don't work there anymore so i don't have to defend them but like i do think that
you know sophos did have it did seem to have better security practices than cyber room did
so after the threat actors found an exploit in the cyber room
product and were actively exploiting that sophos just decided to kill that product altogether
now andrew tells us it's because it was already on its way of being killed but
i don't want to diminish the idea that a cyber attack can have the effect of killing an entire
product line that's a pretty big deal if you ask me anyway somehow the french authorities
investigated the cyber room intrusion and publicly announced that the attack was carried out by apt 31
which is a chinese state-sponsored hacker group
so yeah if it wasn't clear by now it should be the chinese government and military are the ones who
are behind this attack campaign known as pacific rim which has been going on for years at this
point we started to see these actors working on more and more attack types especially t stark you
know we we found him working on like a root kit at the time it was called libxselinux.so and we
found him working on his device and it was like a customized user land root kit so that that was actually a real win for us i remember feeling like okay yeah we've really got a great view of what's happening on these devices here now now we managed to grab these devices from the t stark device but like a week later then he's got a completely new like injection there like a new vulnerability in web assembly and it's kind of
unknown to us and effectively what he was doing was he was in this web assembly um vulnerability he he was injecting like an iframe into the proxy as things move through there and then we found that this thing like i think that's about two weeks or so after we found it had actually been deployed in tibet now this was we found this on this device in tibet
for
for an organization that was basically providing uh support to tibetan exiles so you know he basically
moved from 10 days to deployment yeah and i can't remember which uh i don't know who said it i feel
like a president said something like you know a business isn't going to be able to take fire from
like a scud missile or rocket launch and so we can't expect them to be able to take on attacks
cyber attacks from the nation state actors as well
and at this point you're you're starting to feel confident that this is a nation state of threat
attack on your company to just to and at this point there's five or six different zero days
that they've discovered on you i mean that's got to be some of the most heart-wrenching
gut-sinking feelings to say okay i don't know how we're going to ever stop this attack this
might go on forever like what is your response to this mentally honestly i remember at that point
just feeling exhausted
and i think that's a really good point
you know like this has been months and months and months of
us fighting these you know what is effectively the the PLA you know for for all intents and
purposes and the truth is like who else helps these organizations that organization Tibet
had nowhere near enough resource to be able to deal with this they were lucky that Vlexity
had been doing some pro bono work there we'd reached out and helped them as well but in reality
like if it hadn't been for our graces they would have been stuck and it really comes down to this
weird intersection on the internet of lawlessness like why there's just so many areas that just are
not covered with with anyone I'm in the UK you know we have the the the serious organized crimes
unit and we have the NCSC who protects us in the US of the FBI and the NSA and you know many
countries just don't have anything and this is the part that actually surprised me the most
like who do these people call to you know we we felt like heroes but in reality like who
are we to deal with this you know we're kind of woefully under qualified to deal with a threat
actor at that level you know I mean this felt like almost a military operation yeah suddenly
your war room doesn't feel so up to snuff right like you're you're like man we're we're nowhere
compared to their war room exactly like you know um and I think that's what what what what surprised
me is like we are really on the edge of like what is effectively cyberwarriorism and I think that's
warfare and it started to really tip into that feeling with this but it was it was it was
certainly interesting and you know as a whole you know seeing that that payload being delivered
there and understanding the purpose why they delivered the payload having seen it being built
on a device in shangdu like like 10 10 days two weeks previously it was just one of those crazy
moments of like oh my god like we really see this soup to nuts now when sofos would issue a hot fix
or patch their firewalls they would tell their customer what the update was for like bug fixes
for several security vulnerabilities to learn more visit our knowledge base but sofos discovered that
the threat actors t stark and g big mal were also accessing sofos's site logging in and reading the
knowledge base articles too to see what got patched and they were reading exactly what sofos had fixed
and then developed exploits to get around those patches so the sofos team had to get increasingly
vague with what got fixed to avoid giving the enemy information and i suppose that's a form of
counterintelligence being very careful what information you give your enemy but it kind of
contradicts what i said earlier about don't be evil right if you're not being transparent and
you're hiding what it is you're doing then you might be evil but in this case they had to hide
it because they didn't want their enemies to know this this is so difficult to navigate and at that
point the threat actors understood how the hot fixes
were working and what telemetry sofos was collecting off these firewalls and so they
developed an exploit to disable the hot fixes and to stop the telemetry from going back to sofos to
detect which devices were infected and they took extra steps to hide their presence the threat
actors are developing exploits and they're developing malware and they're coming up with new
techniques for breaking into firewalls and the implant is revealing all of that stuff to the
security team so behind the scenes the security team is rushing into production hot fixes and
patches for the operating system that fix these vulnerabilities before the threat actor even knows
and because they have this ability to send the hot fixes you know not necessarily to every machine
but maybe to every firewall except the ones that the threat actors are using they can fix the whole
universe of firewalls except for the ones that the threat actor is using and i think after you've
tried to deploy your second or third or fourth attack and it just doesn't work and you're
scratching your head because it works in the lab look i can show you it i demonstrated it to these
you know guys in the you know higher ups at the company or whoever is telling me to do this attack
um that it works and and but you know in the wild it suddenly doesn't work i think after two or three
times of of
um shooting blanks you're you're going to start to wonder like hey is there something else going on
and they started to look at you know well what is this information you know what's the firewall
collecting about us and are we inadvertently revealing as as bad guys to the good guys what
we're about to do so yeah so they start looking at telemetry they start looking at log collection
and process lists and they're trying to build out the capabilities to be stealthy
um it's maybe distracting them from building custom malware or developing new exploits but they
have to spend a little bit of energy on uh you know it puts them on the back foot and for the
first time i think this is like one of the cases where you can say yeah there was some there were
some challenges and we had some bad days early on but uh you were forcing the threat actors to
have to make moves to counter us and actually that feels pretty good
um this story just goes on and on there was another rootkit found there's a rootkit number
four libsophos.so yeah so libsophos was the the very custom uh rootkit it was able to edit and
again yeah deleting logs delete you know hiding its presence on the machine uh trying to do
everything as stealthy as possible uh low volume of outbound communication uh and persistence
well they're they're experimenting with everything and and the they've been it seems to me that the
threat actors have been given carte blanche to just try and experiment with all sorts of different
things so so during this period from 20 late 2020 to the end of 2022 we're seeing a huge variety
of different payloads of of exploits it's bad it's bad out there like it's it's kind of like
the wild west and you never know where something's going to come from
at some point they saw the threat actor was trying to develop a eufy boot kit this is malware which
infects the firewall at the bios before the operating system even has a chance to boot up
you know if you if you can get a boot kit into the ufe bios of of a device um there's nothing
that you can do in in the you know user land of the of the operating system and you can't do anything
on the operating system to remove it because it can it's it's running at a level beyond which the
operating system cannot reach yeah a boot kit like this would remain on the system even if you
deleted everything and reinstalled the entire operating system again since it lives in the part
of the computer which loads before the operating system loads uh this was actually kind of scary to
find this uh experimentation happening on one of the threat actor devices they were really trying
to figure out if they could get this boot kit to run on a firewall and they they ended up bricking
the firewall uh it didn't work and uh after we discovered what they were trying to do um the
sofas engineers figured out how to you know change the firmware on the firewall um at that low level
so that it wasn't able to run and they they implemented that in an update uh but that's that's
the scariest thing on all of this I think the ufe boot kit malware on a firewall is the Holy Grail
it's where you you've got malware on a firewall it can't be removed the firewall has to be thrown in
the trash it's scary and you know we've already seen that there's been other firewall vendors
where their recommendation was unplug this box and put it in the trash because it is not safe to
use anymore um
so it makes me wonder because we never get the details from other reports about what happened
whether this was successful with other vendors and whether they were testing this with us and
it just failed because we were watching them and you know stuck a wrench in the works just at the
right moment and made it too much of a pain in the butt for them to keep trying and they just moved
on to the next guy this was very much the kind of end of the world I don't know if you've ever seen
it but it was a really great experience and I think it's a really great thing to do and I think it's
a really great thing to do and I think it's a really great thing to do and I think it's a really great thing to do and I think
it's a really great thing to do and I think it's a really great thing to do and I think it's a really great thing to do and I think
kind of end of my involvement in this because i i actually uh left sophos at this time and went to
work for the company i'm currently working for now you know but i mean from that point i i kept
in really close contact with my my colleagues who were there um and we were sharing intel as things
progressed you know but i mean there were kind of two further published engagements um basically one
in may of 2023 and then one in march of 2024 and then it kind of came to a head you know um
which actually kind of was kind of disappointing in a sense for me because i think i think very
often that this stuff hasn't stopped i mean the devices are significantly more secure now um
software's putting like an inordinate amount of time effort and money into hardening the devices
um i would actually hazard to say that
there's a lot of work that's going on in the industry and there's a lot of work that's going
on in the industry and there's a lot of work that's going on in the industry and there's
a lot of work that's going on in the industry and there's probably the one for a whole company that
probably the one for a whole company that
probably the one for a whole company that actually is secure now um you know
actually is secure now um you know
actually is secure now um you know and in in all seriousness though it's you
and in in all seriousness though it's you
and in in all seriousness though it's you know i think it's one of those aspects
know i think it's one of those aspects
know i think it's one of those aspects of you know you learn from your mistakes
of you know you learn from your mistakes
of you know you learn from your mistakes i mean sophos being incredibly open and
i mean sophos being incredibly open and
i mean sophos being incredibly open and clear about this
I mean kudos to them I mean you know being open about it and you know pub you know publishing
your mistakes and also you know publishing what we did and how we work through this is is super
unique you know and you don't see any other firewall company talking about this and we know
for sure that this stuff was happening across a multitude of other devices the tree says it's
probably happening right now to some other firewall providers we just they just don't know
they don't collect telemetry they don't have the hot fix mechanism allows them to forward defend
you and uh yeah it's an issue it's still an issue one of the actors involved in all of this we
talked about him earlier his name is you know use the handle g big now um that we eventually figured
out his real name you have pictures of him and the guy appears on the FBI's 10 most wanted list
today uh his name is
and he was the researcher at this company called Sichuan uh Sichuan secret silence technology
company yeah Sichuan silence technology company limited right so this guy made it his career
to break into firewalls and find vulnerabilities and then pass them off to people who would take
advantage of them and for all of his efforts
he's in his early 30s he has a 10 million dollar rewards for justice bounty on his head
and he can never travel outside of a non-extradition country in the world ever again
without fearing for arrest and extradition to the United States and it just makes me wonder
if if it really was worth it to him because in in many respects
uh seems like a seems like a nice guy he at one point he had his heart in the right place
so g big now in his early days of working in this field used to post on message boards trying to get
firewall companies to fix their stuff um I can't imagine what happened to turn him to make him break
bad in this way it actually says in the FBI's cyber's most wanted poster that this guy hacked
into 80,000 sofos firewalls
and just because I'm curious I took a look at a few dozen other FBI cyber's most wanted posters
and strangely I don't see any other person listed for hacking into other security vendors so again
hats off for sofos for taking this threat actor so seriously and getting them on the FBI's cyber's
most wanted list the story as as we published it finishes in 2024 not because the attack stopped
but because at a certain point you
just got to put a pin in it and say we're going to stop here because if we keep talking about this
it never ends because the attacks have continued ever since nothing has stopped and if if there's
anything to be said about this is that the cadence has picked up uh it has broadened its scope
we're seeing every security company in the industry in various ways targeted in very similar ways
a big thank you to Andrew Brandt and Craig Jones for coming on the show and telling us this
incredible story of how sofos got targeted by a Chinese state-sponsored threat actor
this story is dang scary to me since the plank field is so unfair a single company
versus a superpower like China and not only that a superpower that's lawless and feels absolutely
no good but it's a superpower that's lawless and feels absolutely no good
no shame from breaking the law you think that after their main guy was arrested by the FBI
they'd pull back and maybe apologize but no they increased their efforts and are hitting harder than
ever against so many security vendors too this show is brought to you by the lovely people who
support the show if you find this show valuable please consider supporting it too as a premium
listener you'll not only show a new ethic for directly supporting the people that you appreciate
but you'll also get bonus episodes of this show and an ad-free version of the show
just visit plus.darknetdiaries.com and become a premium subscriber today thank you
this episode was created by me the lead firewall offender Jack Recider our editor is the port
knocker Tristan Ledger mixing done by Proximity Sound and our intro music is by the mysterious
Breakmaster Cylinder I named my firewall Linebacker because it's great at blocking and tackling
this is Darknet Diaries
this episode was created by me the lead firewall offender Jack Recider our editor is the port
Podcast Summary
Key Points:
In 2018, Chinese state-sponsored attackers breached Sophos's Cyberoam division and stole firewall source code, enabling years of vulnerability research against Sophos products.
In 2020, attackers exploited a SQL injection flaw in Sophos XG Firewalls, compromising roughly 80,000 internet-facing devices and redirecting them to attacker-controlled update domains.
Sophos responded with its first-ever remote hot fix, seized the malicious domains, and worked with Dutch authorities to take down the command-and-control server.
Sophos deployed a secret kernel implant on threat actor devices, giving the security team unprecedented visibility into exploit development and attacker identities.
Investigators identified attackers including "G-Big-Mao" and "T-Stark," linked them to Chinese security firms in Chengdu, and tied the campaign to APT31.
The campaign, dubbed Pacific Rim, involved at least four zero-day exploits, rootkits, bootkit experimentation, and increasingly targeted attacks on government, healthcare, and Uyghur and Tibetan diaspora organizations.
Sophos chose transparency by publicly disclosing the attacks, though it had to keep patch notes vague to avoid tipping off attackers reading its knowledge base.
The attacker known as G-Big-Mao was later placed on the FBI's Cyber Most Wanted list with a $10 million bounty, and the attacks have continued and expanded across the security industry.
Summary:
This episode of Darknet Diaries recounts a multi-year campaign by Chinese state-sponsored hackers against Sophos, a major cybersecurity vendor. The story begins in 2018, when attackers breached Sophos's newly acquired Cyberoam division and stole firewall source code. That theft enabled years of vulnerability hunting, culminating in 2020 with a SQL injection flaw that infected roughly 80,000 internet-facing Sophos XG Firewalls and pointed them at fake update domains. Sophos responded aggressively, issuing its first-ever hot fix, seizing malicious domains through ICANN, and working with Dutch authorities to capture the attacker's command-and-control server.
Sophos then deployed a covert kernel implant on threat actor devices, gaining rare visibility into exploit development and identifying individuals including "G-Big-Mao" and "T-Stark," linked to Chinese security contractors in Chengdu. The campaign, named Pacific Rim, eventually involved at least four zero-days, rootkits, and bootkit experimentation, with attacks targeting government, healthcare, and Uyghur and Tibetan diaspora organizations. Sophos publicly disclosed the incidents, though patch notes grew deliberately vague to avoid informing attackers. One perpetrator was later placed on the FBI's Cyber Most Wanted list with a $10 million bounty, and the campaign continues.
FAQs
Asnarok was a 2020 attack exploiting a SQL injection vulnerability in Sophos XG Firewalls, allowing hackers to breach around 80,000 devices and redirect them to malicious update domains.
Sophos issued its first-ever hot fix to remotely patch customer firewalls without requiring reboots, developed a kernel implant to spy on threat actors, and seized malicious domains with legal help.
The campaign was attributed to Chinese state-sponsored actors, specifically APT31, with individuals like G Big Mao and T Stark linked to Chinese defense contractors.
A hot fix is a real-time software patch applied remotely without rebooting. Sophos used it to quickly secure 80,000 vulnerable firewalls, as many customers wouldn't manually update in time.
Sophos developed a kernel implant to covertly monitor threat actor devices, gathering telemetry on their activities, commands, and exploit development without their knowledge.
They progressed from broad attacks to targeted campaigns against specific organizations in the APAC region, developed workarounds for hot fixes, and experimented with rootkits and bootkits.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.