HomeSecurityPatch on Sophos XG firewalls prevented ransomware attacks

Patch to Sophos XG firewalls prevented ransomware attacks

Sophos XG firewalls

Security firm Sophos yesterday released an update on its investigation into a recent series of attacks. In these attacks , hackers attempted to exploit a zero-day vulnerability in XG firewalls . Sophos acted quickly upon learning of the hacking attempts and issued a hotfix . Apparently, the attackers panicked and modified their attack. So they replaced the original data -stealing payload and attempted to deploy ransomware on corporate networks protected by Sophos firewalls.

Sophos said that XG firewalls, which received the fix, blocked subsequent ransomware installation attempts.

Brief history of the initial attacks

The initial attacks took place between April 22 and 26. In a report published at the time, Sophos said that the attackers had discovered a SQL injection vulnerability (CVE-2020-12271) in the Sophos XG firewall.

Hackers attempted to exploit the vulnerability to attack the firewall's built-in PostgreSQL database server and install malware on the device.

The company said the initial payload was a trojan (which it named Asnarök). The trojan stole usernames and passwords for Sophos firewall accounts.

Additionally, the hackers left behind two files that acted as backdoors , which provided a way to control infected devices.

Sophos, within four days (from the moment it learned about the attacks) issued the fix for XG firewalls, which was automatically installed on all firewalls that had the automatic update option enabled.

ransomware

Attacks changed after the patch

In a new report published yesterday, Sophos said that once the attacks and the patch was released, the attackers changed the type of attack.

The new attack included the following payloads:

  • EternalBlue: SMB exploit in Windows allows attackers to infect computers on the internal network beyond the firewall.
  • DoublePulsar: For gaining access to computers on the internal network.
  • Ragnarok: A crypto-ransomware.

However, according to Sophos, the new attacks failed. In the updated firewalls, all traces of the malware, including both backdoor mechanisms, were removed. Thus, the new attack and successful installation of the ransomware were not possible.

XG firewalls that did not have the automatic update feature enabled or that were not manually updated by administrators were likely infected.

According to the company, this incident highlights the need to constantly update our systems and is a reminder that any IoT device could be used as a base to access Windows machines.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS