Cloud Snooper: The Rootkit That Hid in TCP Source Ports
Sophos discovered a compromised cloud server on its own network in 2018. The attackers planted a rootkit called Snoopy that watched inbound TCP packets. The source port number was the coded instruction — no separate command channel needed. Stolen data exited through the same connection, invisible to the web application firewall. Snoopy printed debug messages in Chinese and used the encryption key “replace with your password”. The team found 11 distinct malware families on the server, including a Windows DLL on a Linux host.
Aznarok: SQL Injection, Dead Man Switches, and Ragnarok Ransomware
In April 2020, a customer reported Linux commands in an XG firewall management field. The attacker exploited a SQL injection bug submitted as a bug bounty the day before. They registered domains with “Sophos” in the name and dropped a payload that stole configuration data encrypted with the password “Gucci”. A dead man switch — an empty file — triggered a call to “Ragnarok from Asgard” if a hot fix deleted it. That call deployed the Ragnarok ransomware via EternalBlue and DoublePulsar, targeting Windows 7 machines. The ransomware included a Chinese language safety check, the first Brandt had seen.
Baja: The Attacker’s Lab and the Tony Stark Connection
Summer 2020 brought a new mass attack, nicknamed Baja, exploiting a buffer overflow in the bookmark feature. Attackers wiped logs and reversed the Aznarok hot fix. Sophos deployed a stealth kernel implant to surveil firewalls that behaved oddly — registered with free webmail accounts like 163.com, connecting from Chinese IP ranges. One cluster used the email “T. Stark”. That firewall hosted a copy of the WinNTI rootkit, tied to APT41, and later Apple/iOS malware linked to the “Evil Eye” campaign targeting diaspora support groups. Sophos patched every firewall except those it assumed were under hostile control.
Personal Panda: Targeted Espionage and the Pygmy Goat Malware
In spring 2022, another bug bounty arrived from a submitter claiming Japanese residence but using Chinese IPs. The exploit chain involved two CVEs — one for firewall access, one for OpenSSL root. Sophos disclosed it to OpenSSL, which patched immediately. Attackers deployed a payload called libsos.so on firewalls protecting high-level government offices. It performed TLS man-in-the-middle decryption to sniff passwords. The UK NCSC nicknamed the sample Pygmy Goat. T. Stark had tested an identical binary on his firewall. The campaign hit Belt and Road countries and diaspora-support organizations.
Covert Channels: Nuclear Regulators and Utility Attacks
Attackers targeted firewalls protecting a country’s nuclear regulatory commission and its national nuclear supplier. They installed Trojanized Java JARs that added backdoor functionality. Termite malware scraped stored credentials and tried to log into internal domain controllers. For the first time, Sophos saw probes against water and power utilities. Other attacks left behind socks proxies, password sniffers, and a webshell hidden in the firmware-update partition. Sophos found eight different malware samples on customer firewalls, including a Metasploit module, GhostRAT, and a custom Go trojan. The bootkit Vector EDK was attempted but never successfully deployed.
Aftermath: 206 Vulnerabilities and the Call for Industry Collaboration
Sophos published a list of 206 serious firewall vulnerabilities through 2023. 44% had a CVSS score of 9.8 or higher. Attackers increasingly turned compromised firewalls into relay beacons to mask their origin. Brandt noted 13 new CVEs per day and an 80% year-over-year rise in known exploited vulnerabilities — more than half from just the first eight months of 2025. He argued that no single company can fix the problem alone and urged the industry to form a mutual-aid ISAC for threat sharing and defense.
Notable Quotes
“the source port is the coded instruction for Snoopy” Andrew Brandt · ▶ 7:29
“they encrypt the data with the password Gucci as in no problem dog, it’s all Gucci” Andrew Brandt · ▶ 11:30
“This is the first ransomware I’d seen that had added Chinese to this safety measure.” Andrew Brandt · ▶ 13:29
“The adversaries are using our own firewalls to conduct our attacks to to conduct attacks against us.” Andrew Brandt · ▶ 30:50
“None of us alone can fix everything.” Andrew Brandt · ▶ 33:45
Key Takeaways
- Chinese threat actors used bug bounties to test exploits before mass attacks.
- Firewalls become relay beacons, hiding attacker origin behind trusted devices.
- Industry needs a shared threat-intel mechanism — no single vendor can defend alone.
About the Speaker(s)
Andrew Brandt is a former investigative journalist who switched careers to work in information security in 2007. He has served as director of threat research and principal researcher at several large cybersecurity companies. He currently serves on the board of World Cyber Health, which operates the Malware Village at Defcon, and is executive director of Elect More Hackers, an organization that recruits and trains technology professionals for elected office. He lives in Boulder, Colorado.