logo

Treasury sanctions Chinese cyber company, employee for 2020 global firewall attack

ID: d97547f0-81e9-5637-b436-078ac99d3de2

STIX ID: report--d97547f0-81e9-5637-b436-078ac99d3de2

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2024-12-10

Date Updated: 2026-04-21

Author: mbracken

...
...

Executive summary: A security researcher at Sichuan Silence discovered and weaponized a zero-day in a firewall product in April 2020, using it to compromise approximately 81,000 firewalls worldwide, exfiltrate usernames and passwords, and attempt deployment of the Ragnarok ransomware; the incident affected thousands of businesses including U.S. critical infrastructure, prompted OFAC sanctions against the individual and company, a DOJ indictment, and a State Department reward offer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.