Custom "Pygmy Goat" malware used in Sophos Firewall hack on govt network
ID: da658e46-3f5a-51e1-b4e7-636551fdf3b5
STIX ID: report--da658e46-3f5a-51e1-b4e7-636551fdf3b5
Feed Name: Bleeping Computer
The NCSC published a technical analysis of 'Pygmy Goat', an x86-32 ELF shared-object rootkit (libsophos.so) used to backdoor Sophos XG firewalls: it hijacks sshd via LD_PRELOAD, detects a magic-bytes SSH backdoor handshake, relays sessions over a Unix socket, receives ICMP-delivered encrypted C2 details and performs TLS connect-backs (using an embedded certificate mimicking FortiGate CA). The report documents advanced persistence, evasion and remote-access capabilities, links to attacks exploiting CVE-2022-1040 on government and partner devices, and includes hashes, YARA and Snort rules and recommended detection steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
