logo

Inside Sophos' 5-Year War With the Chinese Hackers Hijacking Its Devices

ID: 33561d5c-91a6-5cc0-8b00-a05dd276c951

STIX ID: report--33561d5c-91a6-5cc0-8b00-a05dd276c951

Feed Name: WIRED Security

Threat Score
88/100

Date Published: 2024-10-31

Date Updated: 2026-04-26

Author: Andy Greenberg

...
...

Sophos uncovered a multi-year intrusion campaign by Chinese-linked hackers who first compromised a Cyberoam display machine and then used rootkits and zero-day exploits in Sophos appliances to deploy the Asnarök trojan and build a global botnet of compromised firewalls ("operational relay boxes"). The campaign involved exploitation of multiple zero-days, mass infections of tens of thousands of devices, and strategic targeting of security products to enable broader operations against customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.