ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-12271
SQL Injection RCE in Sophos SFOS Firewalls with WAN-Exposed Admin or User Portal

CVE-2020-12271 is a SQL injection flaw (CWE-89) in the Sophos firewall operating system (SFOS) firmware that runs Sophos's firewall appliances. It is triggered when the appliance's administration (HTTPS) service or its User Portal is exposed on the WAN (internet-facing) zone, which lets remote attackers inject SQL through those services and achieve code execution on the device. Successful exploitation gives attackers remote code execution that can be used to exfiltrate usernames and hashed passwords for local device administrators, portal administrators, and user accounts used for remote access; passwords stored in external Active Directory or LDAP directories are not exposed. Affected organizations are those running Sophos SFOS with the HTTPS admin interface or User Portal reachable from the internet; the source data does not specify affected version ranges, so defenders should consult Sophos's advisories for affected and fixed releases. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS estimates a 42.4% probability of exploitation in the next 30 days (99th percentile), and no public proof-of-concept is known.

Do: Immediately update SFOS to a current patched release per Sophos's upgrade instructions, which is CISA's required action for federal agencies. As an interim mitigation, remove the HTTPS administration service and User Portal from the WAN zone or restrict access to trusted source addresses. Because ransomware actors are known to exploit this flaw, review firewall logs for signs of intrusion and rotate local device-admin, portal-admin, and remote-access user credentials, as only those hashes could have been exfiltrated (external AD/LDAP passwords were not at risk).

9.842% KEV ransomware PoC
  • Sophos SFOS (Sophos firewall operating system)
largetens of thousands (order of magnitude 10,000-100,000) of internet-exposed Sophos firewall admin/portal services
CVE-2020-15069
Unauthenticated Buffer Overflow RCE in Sophos XG Firewall

CVE-2020-15069 is a critical buffer overflow (CWE-120) in the HTTP/S Bookmarks feature used for clientless access in Sophos XG Firewall, affecting firmware versions 17.x through v17.5 MR12. The flaw is reachable over the network without credentials or user interaction, so an unauthenticated attacker can trigger it by sending crafted requests to the exposed bookmarks functionality. Successful exploitation yields remote code execution on the firewall with high impact on confidentiality, integrity, and availability. Any organization running Sophos XG Firewall 17.x through v17.5 MR12 is affected, especially firewalls with the clientless-access feature enabled or management interfaces reachable from the internet. Sophos published hotfix HF062020.1 for all firewalls running v17.x, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, indicating confirmed in-the-wild exploitation (EPSS puts the 30-day exploitation probability at about 10.7%).

Do: Apply hotfix HF062020.1, which Sophos published for all firewalls running v17.x, or upgrade to a current supported release, prioritizing internet-exposed devices. Verify the hotfix is actually installed rather than assuming auto-update succeeded, and disable or restrict the clientless HTTP/S Bookmarks feature as interim mitigation. Review firewall logs for signs of unexpected access or compromise, since exploitation has been confirmed in the wild.

9.811% KEV
  • sophos XG Firewall firmware 17.x through v17.5 MR12
mass≈ hundreds of thousands of firewall deployments, with likely tens of thousands still running unpatched v17.x (internet-wide scans have historically shown…
CVE-2020-29574
Unauthenticated SQL Injection in Sophos CyberoamOS WebAdmin

CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.

Do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.

9.85% KEV ransomware
  • Sophos CyberoamOS (CROS) - WebAdmin all versions through 2020-12-04 (CISA date-based range); product is EoL/EoS
largetens of thousands of deployed appliances (installed-base estimate; internet-exposed WebAdmin consoles likely in the low thousands)
CVE-2022-1040
Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS)

CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw.

Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates.

9.8100% KEV PoC ×2
  • Sophos Firewall (SFOS) v18.5 MR3 and older
largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances
CVE-2022-3236
Unauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin)

CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure.

Do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied.

9.899% KEV
  • Sophos Firewall (User Portal and Webadmin) v19.0 MR1 and older
masshundreds of thousands of deployed Sophos Firewall appliances; tens of thousands of User Portal/Webadmin instances internet-exposed per public scans
Full article1,130 words · extracted from thehackernews.com · click to collapse

The U.S. Federal Bureau of Investigation (FBI) has sought assistance from the public in connection with an investigation involving the breach of edge devices and computer networks belonging to companies and government entities.

"An Advanced Persistent Threat group allegedly created and deployed malware (CVE-2020-12271) as part of a widespread series of indiscriminate computer intrusions designed to exfiltrate sensitive data from firewalls worldwide," the agency said.

"The FBI is seeking information regarding the identities of the individuals responsible for these cyber intrusions."

The development comes in the aftermath of a series of reports published by cybersecurity vendor Sophos chronicling a set of campaigns between 2018 and 2023 that exploited its edge infrastructure appliances to deploy custom malware or repurpose them as proxies to fly under the radar.

The malicious activity, codenamed Pacific Rim and designed to conduct surveillance, sabotage, and cyber espionage, has been attributed to multiple Chinese state-sponsored groups, including APT31, APT41, and Volt Typhoon. The earliest attack dates back to late 2018, when a cyber-attack was aimed at Sophos' Indian subsidiary Cyberoam.

"The adversaries have targeted both small and large critical infrastructure and government facilities, primarily in South and Southeast Asia, including nuclear energy suppliers, a national capital's airport, a military hospital, state security apparatus, and central government ministries," Sophos said.

Some of the subsequent mass attacks have been identified as leveraging multiple then zero-day vulnerabilities in Sophos firewalls – CVE-2020-12271, CVE-2020-15069, CVE-2020-29574, CVE-2022-1040, and CVE-2022-3236 – to compromise the devices and deliver payloads both to the device firmware and those located within the organization's LAN network.

"From 2021 onwards the adversaries appeared to shift focus from widespread indiscriminate attacks to highly targeted, 'hands-on-keyboard' narrow-focus attacks against specific entities: government agencies, critical infrastructure, research and development organizations, healthcare providers, retail, finance, military, and public-sector organizations primarily in the Asia-Pacific region," it said.

Beginning mid-2022, the attackers are said to have focused their efforts on gaining deeper access to specific organizations, evading detection, and gathering more information by manually executing commands and deploying malware like Asnarök, Gh0st RAT, and Pygmy Goat, a sophisticated backdoor cable of providing persistent remote access to Sophos XG Firewalls and likely other Linux devices.

"While not containing any novel techniques, Pygmy Goat is quite sophisticated in how it enables the actor to interact with it on demand, while blending in with normal network traffic," the U.K. National Cyber Security Centre (NCSC) said.

"The code itself is clean, with short, well-structured functions aiding future extensibility, and errors are checked throughout, suggesting it was written by a competent developer or developers."

The backdoor, a novel rootkit that takes the form of a shared object ("libsophos.so"), has been found to be delivered following the exploitation of CVE-2022-1040. The use of the rootkit was observed between March and April 2022 on a government device and a technology partner, and again in May 2022 on a machine in a military hospital based in Asia.

It comes with the "ability to listen for and respond to specially crafted ICMP packets, which, if received by an infected device, would open a SOCKS proxy or a reverse shell back-connection to an IP address of the attacker's choosing."

The deployment of Pygmy Goat has been attributed to a Chinese threat actor internally tracked by Sophos as Tstark, which shares links to the University of Electronic Science and Technology of China (UESTC) in Chengdu.

Sophos said it countered the campaigns in its early stage by deploying a bespoke kernel implant of its own on devices maintained by Chinese threat actors to carry out malicious exploit research, including machines owned by Sichuan Silence Information Technology's Double Helix Research Institute, thereby gaining visibility into a "previously unknown and stealthy remote code execution exploit" in July 2020.

A follow-up analysis in August 2020 led to the discovery of a lower-severity post-authentication remote code execution vulnerability in an operating system component, the company added.

Furthermore, the Thoma Bravo-owned company said it has observed a pattern of receiving "simultaneously highly helpful yet suspicious" bug bounty reports at least twice (CVE-2020-12271 and CVE-2022-1040) from what it suspects are individuals with ties to Chengdu-based research institutions prior to them being used maliciously.

The findings are significant, not least because they show that active vulnerability research and development activity is being conducted in the Sichuan region, and then passed on to various Chinese state-sponsored frontline groups with differing objectives, capabilities, and post-exploitation techniques.

"With Pacific Rim, we observed [...] an assembly line of zero-day exploit development associated with educational institutions in Sichuan, China," Chester Wisniewski said. "These exploits appear to have been shared with state-sponsored attackers, which makes sense for a nation-state that mandates such sharing through their vulnerability-disclosure laws."

Edge network devices have increasingly become high-value targets for both initial access and persistence, in some cases even used as operational relay boxes (ORBs) to breach onward targets and obfuscate the true origin of attacks.

In recent months, People's Republic of China (PRC) threat actors like Volt Typhoon and Storm-0940 have been observed leveraging botnets like KV-Botnet and Quad7 comprising infected routers and other edge devices to conduct reconnaissance and password-spraying attacks.

Sophos' Chief Information Security Officer (CISO) Ross McKerchar told The Hacker News that the company has not observed instances where these botnets have been put to use as part of the Pacific Rim campaigns.

"Edge devices are a key target for PRC-based actors, and the rate at which they are being targeted is increasing," McKerchar said.

"Our assessment is that the requirement for PRC-based researchers to share vulnerabilities with the MIIT, a government entity which the Atlantic Council report shows has links to APT groups, is a key component which is providing the underlying fuel and vulnerabilities to power these attacks."

The increased targeting of edge network devices also coincides with a threat assessment from the Canadian Centre for Cyber Security (Cyber Centre) that revealed at least 20 Canadian government networks have been compromised by Chinese state-sponsored hacking crews over the past four years to advance its strategic, economic, and diplomatic interests.

It also accused Chinese threat actors of targeting its private sector to gain a competitive advantage by collecting confidential and proprietary information, alongside supporting "transnational repression" missions that seek to target Uyghurs, Tibetans, pro-democracy activists, and supporters of Taiwanese independence.

Chinese cyber threat actors "have compromised and maintained access to multiple government networks over the past five years, collecting communications and other valuable information," it said. "The threat actors sent email messages with tracking images to recipients to conduct network reconnaissance."

(The story was updated after publication to include responses from Sophos.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/fbi-seeks-public-help-to-identify.html