HomeSecurityAsnarök malware: Attacks Sophos firewall and steals credentials

Asnarök malware: Attacks Sophos firewall and steals credentials

Some Sophos firewall products were attacked by new Trojan malware, dubbed Asnarök by Sophos researchers, which aimed to steal usernames and hashed passwords starting on April 22 according to an official timeline.

The malware exploits a zero-day SQL injection vulnerability that can lead to remote code execution in various firewalls.

"This attack targets Sophos products and was apparently intended to steal sensitive information from firewalls," Sophos said.

Sophos firewall

The Asnarök malware payload was downloaded to attack firewall devices in the form of multiple Linux shell scripts after exploiting a zero-day SQL injection remote code execution vulnerability.

The exploit used to download the payload also dropped a shell script that made the malware installer script executable and launched it on compromised devices.

Asnarök “also modified services to ensure that it ran every time the firewall was started – serving as a circular persistence mechanism for the malware,” according to Sophos’ analysis.

Asnarök steals firewall credentials

As researchers discovered while examining the Trojan, the malware is specifically designed to collect and extract usernames and firewall passwords, as well as some system information.

Sophos said that credentials associated with external authentication systems, such as Active Directory and LDAP, were not exposed and were not targeted by Asnarök.

Furthermore, Sophos has no evidence that any of the data collected by the attackers with the help of the Asnarök Trojan was successfully extracted.

The malware can collect the following firewall information:

  • The firewall license and serial number
  • A list of the email addresses of the user accounts that were stored on the device, followed by the primary email belonging to the firewall administrator account
  • Firewall user names, usernames, encrypted form of passwords, and SHA256 hash of the administrator account password. Passwords were not stored in plain text.
  • A list of user IDs that are allowed to use the firewall for SSL VPN and accounts that are allowed to use clientless VPN connections.

Asnarök also queries the internal database of infected firewalls to collect information about the operating system, amount of RAM and CPU, uptime information, and users' IP address assignment permissions, among other things.

All data is written to an Info.xg file, archived, encrypted, and then sent to servers controlled by the attackers.

Customers are notified if their devices have been compromised

Sophos blocked the domains used by Asnarök on April 22 and April 23 and released patches to affected firewall devices on April 23 and April 24.

The final security update for the XG Firewall zero-day vulnerability was ready by the afternoon of April 25, when Sophos began rolling it out to all XG Firewall units with automatic updates enabled.

Customers who do not have automatic updating enabled on their firewalls can follow these instructions to manually install the hotfix.

Sophos will automatically display alerts in the XG Firewall management interface to inform customers whether their units have been compromised or not.

If you are notified that your device has been infected, Sophos recommends taking the following additional steps to ensure your firewall is fully secure:

1. Restore portal administrator and device administrator accounts

2. Restart XG devices

3. Reset passwords for all local user accounts

4. Although passwords were hashed, it is recommended to reset passwords for accounts where XG credentials may have been reused

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS