Nation-State

FBI Seeking Information on Chinese Hackers Targeting Sophos Firewalls

The FBI is asking for information on the Chinese threat actors targeting Sophos edge devices to compromise private and government entities.

The FBI is asking for information on the Chinese threat actors targeting Sophos edge devices to compromise private and government entities.

The FBI is asking for public help in identifying the hackers behind a years-long campaign targeting Sophos edge devices.

The campaign, brought to light last week by Sophos itself and ongoing since as early as 2018, was attributed to China-linked advanced persistent threat (APT) actors such as APT41, APT31, and Volt Typhoon.

As part of the attacks, the APTs exploited multiple zero-day vulnerabilities in internet-facing assets to gain code execution and then leveraged additional exploits to deploy malware with root privileges on the vulnerable devices.

“Beginning in early 2020 and continuing through much of 2022, the adversaries spent considerable effort and resources in multiple campaigns targeting devices with internet-facing web portals,” Sophos said.

One of the zero-days, tracked as CVE-2020-12271 and affecting Sophos’ XG Firewall, was exploited in April 2020 to deploy the Asnarök malware. Working with European law enforcement, the company took down the server hosting the malware.

Sophos says that, for over half a decade, it has been fighting a cat-and-mouse battle with the Chinese hackers, deploying a custom implant to monitor the attackers’ movements and identify their exploits and TTPs.

Advertisement. Scroll to continue reading.

While Sophos did not share information on any of the organizations that might have been compromised in these attacks, the FBI says that both private companies and government entities have fallen victim to the intruders.

“As described by Sophos Ltd. in a recently released cyber security report, on April 22, 2020, an Advanced Persistent Threat group allegedly created and deployed malware (CVE-2020-12271) as part of a widespread series of indiscriminate computer intrusions designed to exfiltrate sensitive data from firewalls worldwide. The FBI is seeking information regarding the identities of the individuals responsible for these cyber intrusions,” the FBI said in a notice (PDF) on Friday.

The agency is encouraging individuals who might have information on the attackers to contact it using messaging services such as WhatsApp, Signal, and Telegram, or to contact local FBI offices, American embassies, or consulates, or submit a tip online.

The UK’s National Cyber Security Centre (NCSC) has published technical documentation on Pygmy Goat, a sophisticated backdoor that has been planted on hacked Sophos XG firewalls.

Related: Canada Says Chinese Reconnaissance Scans Targeting Government Organizations

Related: AP Sources: Chinese Hackers Targeted Phones of Trump, Vance, People Associated With Harris Campaign

Related: Chinese State Hackers Main Suspect in Recent Ivanti CSA Zero-Day Attacks

Related: Chinese Hackers Seen Targeting Ukraine Post-Invasion

Related Content

Nation-State

Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.

Phishing

The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.

Government

The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances

Nation-State

Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information.

Cybercrime

Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.

Cybercrime

The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.

Malware & Threats

Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.

Nation-State

The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version