US sanctions Chinese firm for hacking firewalls in ransomware attacks
ID: 4f3c5093-88b0-560c-b7df-2bc6b42734bd
STIX ID: report--4f3c5093-88b0-560c-b7df-2bc6b42734bd
Feed Name: Bleeping Computer
Threat Score
The U.S. Treasury and DOJ have linked Sichuan Silence and employee Guan Tianfeng to an April 2020 campaign that exploited a Sophos XG zero-day (CVE-2020-12271) to compromise ~81,000 firewalls (including ~23,000 in the U.S.), exfiltrate credentials, and attempt to trigger Ragnarok ransomware via an Asnarök toolkit; the action led to sanctions, an unsealed indictment, and a multi-million-dollar reward offer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
