logo

US names Chinese national it alleges was behind 2020 attack on Sophos firewalls

ID: c5c432a3-ab7b-546d-b0c1-854de17d2044

STIX ID: report--c5c432a3-ab7b-546d-b0c1-854de17d2044

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-12-11

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

US authorities allege that a China-linked security researcher and his employer exploited a critical SQL injection (CVE-2020-12271) in Sophos XG firewalls in April 2020, compromising approximately 81,000 devices (including at least one US government agency). The attackers used a spoofed domain (sophosfirewallupdate.com) to deliver malware that exfiltrated firewall data to a Chinese IP, attempted (but failed) to pivot to deliver Ragnarok ransomware after patching was detected, and have since been indicted, sanctioned, and made the subject of a multi-million-dollar reward.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.