logo

Custom "Pygmy Goat" malware used in Sophos Firewall hack on govt network

ID: da658e46-3f5a-51e1-b4e7-636551fdf3b5

STIX ID: report--da658e46-3f5a-51e1-b4e7-636551fdf3b5

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The NCSC published a technical analysis of 'Pygmy Goat', an x86-32 ELF shared-object rootkit (libsophos.so) used to backdoor Sophos XG firewalls: it hijacks sshd via LD_PRELOAD, detects a magic-bytes SSH backdoor handshake, relays sessions over a Unix socket, receives ICMP-delivered encrypted C2 details and performs TLS connect-backs (using an embedded certificate mimicking FortiGate CA). The report documents advanced persistence, evasion and remote-access capabilities, links to attacks exploiting CVE-2022-1040 on government and partner devices, and includes hashes, YARA and Snort rules and recommended detection steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.