logo

Pacific Rim: Sophos’ 6 Year Battle To Beat Back China State Hackers

ID: abdaf559-4b60-53a6-81c0-dae3f05f5638

STIX ID: report--abdaf559-4b60-53a6-81c0-dae3f05f5638

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2024-11-21

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Sophos's Pacific Rim investigation describes a multi-year, state‑sponsored Chinese APT campaign that used sophisticated cloud-based pivoting (AWS SSM), assembled botnet-like "ORBs," exploited zero‑day vulnerabilities, and deployed stealthy rootkits and bootkits to compromise perimeter and customer devices; Sophos employed a targeted implant and improved telemetry to detect activity, intercept a zero‑day exploit, patch vulnerabilities, and inform mitigation, while highlighting systemic risks from legacy/end-of-life devices and the need for stronger secure development and coordinated responses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.