Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Hackers tried to install ransomware through vulnerability in Sophos XG

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,903
Reaction score
942
Points
212
Awards
2
  • trusted user
  • Rich User
After fixing the vulnerability, cybercriminals were forced to change their tactics.

02ac23fab47c1f339ce99655acbadf74.png


On Thursday, May 21, Sophos released new cyber attacks on its XG firewalls.

Recall last month that it became known about the exploitation of the zero-day vulnerability in Sophos XG firewalls. According to the researchers, upon learning of the incident, the manufacturer released emergency security updates, and attackers quickly changed their tactics, replacing the original payload, infostiller, extortionate software. As the researchers found, the firewalls on which the patch was installed blocked subsequent attempts to install ransomware.

Initial cyberattack attempts were made on April 22-26. Attackers exploited a vulnerability (CVE-2020-12271) on Sophos XG firewalls that allowed for SQL injection. Attackers aimed at the built-in PostgreSQL server and installed malware on the device.

According to Sophos, the original payload was the Asnarök Trojan, which collects usernames and passwords for accessing the Sophos firewall. In addition, the attackers left two files playing the role of backdoors, providing them with control over the devices.

The manufacturer quickly released an emergency update, not all vulnerable devices were automatically sent out, and the attackers were forced to change their tactics. A new attack includes the following steps:

  • EternalBlue - exploit for a vulnerability in Windows SMB to infect internal networks protected by a firewall;
  • DoublePulsar - implant for the Windows kernel, providing access to computers on the internal network;
  • Ragnarok - Ransomware.
According to the researchers, the new tactic does not work. The emergency update released by Sophos removes all traces of malware, including two backdoors, and as a result, the final malware load (ransomware) is not installed.
__________________
 
Ad End 1 February 2024
Top