Episode Summary
Executive Summary: The episode recounts Sophos’s multi-year battle with a Chinese state-linked threat actor that exploited firewall vulnerabilities, stole source code, deployed malware, and targeted specific victims. Sophos responded with unprecedented transparency, hotfixes, telemetry, and even stealth implants to observe attackers and preempt future exploits.
Main Topics: Initial source-code theft and the first compromise (Priority: 5/5): Attackers first breached Cyberoam infrastructure, pivoted from a small Linux device, and reached the firewall source-code repository, enabling later exploitation of Sophos products. Mass exploitation of public-facing Sophos firewalls (Priority: 5/5): A SQL injection in the XG firewall web UI was used to compromise roughly tens of thousands of internet-facing devices, allowing attackers to alter update settings and steal configs/passwords. Sophos’s unusual response: hotfixes, telemetry, and transparency (Priority: 5/5): Because customers could not be relied on to patch quickly enough, Sophos pushed remote hotfixes and publicly disclosed the incident, choosing broad transparency over secrecy. Threat-actor attribution and OSINT investigation (Priority: 4/5): Sophos linked activity to specific researchers/accounts such as GBigMao and T.Stark in Chengdu/China, using telemetry, trial licenses, email addresses, and behavior patterns to map the campaign. Stealth monitoring and ethical gray areas (Priority: 4/5): Sophos deployed a kernel implant to collect deeper telemetry from suspected attacker-controlled devices, raising questions about spyware, consent, and vendor authority over customer equipment. Pacific Rim campaign evolution and additional zero-days (Priority: 5/5): The attackers iterated through multiple campaigns (e.g., Ragnarok, Baja), web shells, rootkits, bootkits, and later highly targeted attacks on specific organizations and sectors, especially in APAC. Broader industry and nation-state implications (Priority: 4/5): The story suggests similar attacks likely target other firewall vendors too, but many lack Sophos’s telemetry and response capabilities, making such campaigns hard to detect and attribute.
Key Arguments: The attack was highly sophisticated and required access to source code, making ordinary criminal motives less likely than a state-backed operation. Sophos’s hotfix capability was necessary because expecting 80,000+ customers to patch immediately would have left many exposed. Radical transparency helped customers, the public, and defenders, even though it risked reputational damage. The attackers adapted quickly once they observed Sophos’s defenses, showing an ongoing offensive-defensive arms race. Sophos’s kernel implant and sinkholing efforts were framed as defensive intelligence gathering against devices believed to be attacker-owned. The campaign evolved from broad exploitation to targeted operations against governments, critical infrastructure, healthcare, finance, and activist-support organizations. The combination of telemetry, OSINT, and forensic analysis allowed Sophos to attribute devices and identify repeated actor behavior patterns. The discovery of multiple zero-days across successive rounds strongly supports a long-term nation-state campaign rather than a one-off intrusion.
Data Points: Initial compromise year: 2018 - First source-code theft and Cyberoam intrusion occurred in this period. Hotfix response delay: 4 days - Andrew and Craig describe the initial incident response and remediation as happening in four days. Affected firewalls: about 80,000 - Sophos estimated roughly this many internet-facing firewalls were compromised; an FBI report mentioned 88,000. FBI report estimate: 88,000 - Referenced as the number of affected devices in an FBI report. Bug bounty payout: about $10,000 - Sophos paid a bug bounty for the suspicious SQL injection report. One device observed early: 1 device - Telemetry showed a single suspicious device hit around February before the larger campaign. Second-round affected devices: 175–200 - Approximate number of devices affected in the Baja/web-shell phase. Actors identified: about 7 different actors - Sophos eventually tracked multiple individuals or teams working on different pieces of the campaign. Exploit timing: 10 days to 2 weeks - A payload seen on a threat-actor lab device was later deployed against a target within roughly this timeframe. Reward: $10 million - The FBI reward for Guan Tian Feng (GBigMao) on the Cyber’s Most Wanted list. Targeting region: APAC - Later attacks focused heavily on Asia-Pacific entities, including Taiwan, Pakistan, the Philippines, and others. Timeline of later published incidents: May 2023 and March 2024 - Craig notes further published engagements after the main earlier incidents.
Pivotal Quotes: "The more information that you get out, the better protected people are." — Andrew Brandt: Explaining why Sophos chose public disclosure and transparency during the incident. "If you're afraid to let the public know exactly how you operate because you think it's going to look bad on you... then either stop doing it or go public with it." — Jackie Sider: Reflecting on the ethics of secret monitoring and defensive behavior by vendors. "This isn't just like SOFOS firewalls. We've seen other vendors' devices on the same subnet alongside the Sophos firewall." — Craig Jones: Describing how the implant revealed broader cross-vendor targeting.
Implications: Firewall vendors are now high-value targets in long-running state-sponsored campaigns. Defenders need telemetry, rapid patching, and clear disclosure, but also must confront the ethics of deep monitoring and remote intervention on customer devices.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.