logo

China-Based Hacker Charged for Conspiring to Develop and Deploy Malware That Exploited Tens of Thousands of Firewalls Worldwide

ID: f549c2c7-a1ba-5120-8c62-0380f56cc7c3

STIX ID: report--f549c2c7-a1ba-5120-8c62-0380f56cc7c3

Feed Name: DataBreaches.Net

Threat Score
86/100

Date Published: 2024-12-10

Date Updated: 2026-04-19

Author: Dissent

...
...

The DOJ unsealed an indictment against PRC citizen Guan Tianfeng for conspiring to exploit Sophos firewall zero‑day CVE‑2020-12271 in 2020, deploying malware across ~81,000 devices worldwide (including a U.S. agency) to steal data and trigger ransomware-like encryption if removal was attempted; the actors used spoofed Sophos‑themed domains, while Sophos’ rapid response blunted the impact. The case links Guan and employer Sichuan Silence to PRC government work, and is accompanied by FBI information requests, State Department rewards, and OFAC sanctions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.