Sophos has revealed a series of reports dubbed “Pacific Rim” that detail how the cybersecurity has been battling Chinese hackers for more than 5 years, as they targeted networking devices worldwide, including Sophos’s.
See also: Sophos acquires SecureWorks for $859 million

For years, cybersecurity firms have warned businesses that Chinese hackers are exploiting flaws in cutting-edge networking devices to install custom malware that allows them to monitor network communications, steal credentials, or act as proxies for relayed attacks.
These attacks have targeted well-known manufacturers, including Fortinet, Barracuda, SonicWall, Check Point, D-Link, Cisco, Juniper, NetGear, Sophos, and many others.
Sophos has attributed this activity to multiple Chinese hackers, known as Volt Typhoon, APT31, and APT41/Winnti, who have been known to target networking devices in the past.
The company says it began battling hackers in 2018, when they targeted the headquarters of Cyberoam, a Sophos subsidiary based in India. Researchers believe that's when malicious actors began investigating attacks on network devices.
See also: Citrix and Sophos affected by leap year bugs
Since then, hackers have increasingly used zero-day and known vulnerabilities to target cutting-edge networking devices.

Sophos believes that many of the zero-day flaws are developed by Chinese researchers who not only share them with vendors, but also with the Chinese government and state-sponsored hackers.
Over the years, Chinese hackers have evolved their tactics to use memory-only malware, advanced persistence techniques, and the use of compromised network devices as proxy networks of massive operational relay boxes (ORBs) to evade detection.
While many of these attacks put cybersecurity researchers on the defensive, Sophos also had the opportunity to counterattack by placing custom implants on devices that were known to have been compromised. These implants allowed Sophos to collect valuable data about the Chinese hackers, including a UEFI bootkit that was observed to be deployed on a networking device.
See also: Sophos: Upgrades RCE patch after attacks
Chinese hackers are a frequent topic of discussion in global cybersecurity .Their activities often attract attention due to their sophisticated techniques and alleged support from state-sponsored entities. These cyber intrusions can target a wide range of sectors, including finance, technology, and government, with the aim of stealing sensitive data, intellectual property, and destabilizing critical infrastructure. As the digital landscape evolves, the challenges posed by such hacking require increased international cooperation and robust cybersecurity measures to protect valuable information and maintain global security.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
