DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
ID: 0af7978e-0c64-56f0-82d1-7a150f42be38
STIX ID: report--0af7978e-0c64-56f0-82d1-7a150f42be38
Feed Name: Volexity Blog
Threat Score
Volexity investigated a Sophos Firewall breach in March 2022 where a zero-day RCE (linked to CVE-2022-1040) was exploited by the Chinese APT 'DriftingCloud' to install a CLASS-based webshell, create persistence, perform DNS MITM to harvest CMS session cookies, and pivot to external WordPress hosts to deploy multiple RATs (PupyRAT, Pantegana, Sliver); the report includes technical details, IOCs, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
