How a TV Leaderboard Device Started a Five-Year Investigation

▶ Watch (05:02)

Sophos acquired an Indian company called Cyber Roam in 2018. While onboarding the new staff, security operations found a small computer attached to the back of a TV monitor displaying a sales leaderboard. It contained GhostRAT, network-scanning utilities, and an unusual connection to a cloud server. Following that trail, analysts found 11 malware samples total, including a DLL written for Windows on a machine running Linux.

The centerpiece was a deep-packet inspection engine the attackers named Snoopy. See the Cloud Snooper packet-inspection demo diagram (04:15): Snoopy watches the source port number of each inbound TCP packet. A coded port triggers data theft; the stolen data exits through the same connection, invisible to the cloud firewall. Debug strings printed in Chinese and C2 hostnames referencing Nepal’s country TLD tied the implant to a specific region.

Asnarok: The First Mass Firewall Attack

▶ Watch (08:12)

A customer screenshot showed Linux commands inside a Sophos XG firewall field that should hold a remote management address. The commands pointed to sofos firewallupdate.com.

“Sofos didn’t own that domain.” Andrew Brandt

The attack, Asnarok, used SQL injection to execute arbitrary code on every internet-facing XG firewall. Post-mortem analysis found the precise method had been submitted as a bug bounty one day before the attack began. The attacker registered domains with “Sophos” in the name just beforehand. They dropped a payload called “to own” that exfiltrated firewall configs encrypted with the password “Gucci.” To survive hot fix cleanup, the attacker deployed a Asnarok dead man switch (11:02): an empty file monitored by the malware. Deletion triggered a call to “Ragnarok from Asgard,” launching Ragnarok ransomware against LAN-side Windows machines. The ransomware failed; EternalBlue only reliably hit Windows 7, which had reached end of life that January.

Sophos Plants Its Own Implant

▶ Watch (13:50)

After sinkholing the Ragnarok domain, Sophos discovered small business routers and firewalls calling back to it. The security operations team built a kernel-level implant and deployed it to suspicious devices only, giving them a real-time view over threat actors’ shoulders. The first target: a firewall registered to a free 163.com account from a Chengdu IP range. The implant caught WinNTI rootkit samples being tested before deployment, tying the operator to APT41. Sophos withheld hot fixes from compromised devices, preventing the rootkit from spreading to any customer network.

Targeted Operations and Critical Infrastructure

▶ Watch (22:30)

After the CyberRoam mass attack, attributed to APT31, every subsequent Sophos XG exploit targeted specific governments or industries rather than all customers at once. Spring 2022 brought Personal Panda: a bug bounty submitted from Japan-listed IPs that traced to China, weaponized the next day. One payload dropped a Pygmy Goat TLS-stripping implant (24:46) on firewalls protecting a high-level government office, stripping HTTPS to steal passwords. A later campaign hit a country’s nuclear regulatory agency and energy supplier, deploying Termite to scrape firewall credentials and pivot to domain controllers.

The Scorecard and What the Industry Owes Its Customers

▶ Watch (30:28)

Security operations catalogued 206 serious firewall CVEs through 2023. 44% scored 9.8 or higher on CVSS. Compromised firewalls are now repurposed as operational relay beacons (ORBs), routing attacker traffic so it appears to originate elsewhere.

“The adversaries are using our own firewalls to conduct attacks.” Andrew Brandt

130 new CVEs appear daily; known exploited vulnerabilities rose 80% year over year. G Big Mau was identified as Juan Tianfang, a 30-year-old at Sichuan Silence Information Technology Company, now carrying a $10 million US reward for his arrest.

Notable Quotes

Sofos didn’t own that domain. Andrew Brandt · ▶ 9:00

The adversaries are using our own firewalls to conduct attacks. Andrew Brandt · ▶ 31:05

None of us alone can fix everything. Andrew Brandt · ▶ 34:23

Key Takeaways

  • China-linked actors ran three distinct attack phases against Sophos firewalls from 2018 to 2023, shifting from mass exploitation to precision targeting.
  • 44% of 206 serious firewall CVEs catalogued through 2023 scored 9.8 or higher on CVSS, while 130 new CVEs appear every day.
  • Compromised firewalls are now being converted into operational relay beacons that route attacker traffic and disguise its origin.