logo

US sanctions Chinese firm for hacking firewalls in ransomware attacks

ID: 4f3c5093-88b0-560c-b7df-2bc6b42734bd

STIX ID: report--4f3c5093-88b0-560c-b7df-2bc6b42734bd

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

The U.S. Treasury and DOJ have linked Sichuan Silence and employee Guan Tianfeng to an April 2020 campaign that exploited a Sophos XG zero-day (CVE-2020-12271) to compromise ~81,000 firewalls (including ~23,000 in the U.S.), exfiltrate credentials, and attempt to trigger Ragnarok ransomware via an Asnarök toolkit; the action led to sanctions, an unsealed indictment, and a multi-million-dollar reward offer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.