HomeSecurityPygmy Goat backdoor detected in compromised Sophos XG Firewall

Pygmy Goat backdoor detected in compromised Sophos XG Firewalls

NCSC researchers discovered a sophisticated backdoor called “ Pygmy Goat ” that had been deployed on compromised Sophos XG Firewall devices .

See also: North Korean hackers use new VeilShell Backdoor

Pygmy Goat backdoor

The malware, discovered by the National Cyber ​​Security Center (NCSC), provides attackers persistent access and powerful capabilities to maintain their foothold in victims' networks.

The Pygmy Goat backdoor is a native x86-32 ELF shared object that leverages the LD_PRELOAD technique to inject itself into the SSH daemon (sshd) process of infected devices. This allows the malware to connect to critical functions and intercept network traffic through the firewall. The backdoor uses multiple methods to establish command and control (C2) communications.

It can monitor incoming ICMP packets for specially crafted messages containing encrypted callback information. In addition, it hooks into the SSH accept function to look for a specific byte sequence in incoming connections, which can be used as an alternative C2 channel.

See also: Spear-phishing campaign infects recruiters with the More_eggs backdoor

Once activated, the Pygmy Goat backdoor provides attackers with a number of capabilities, including:

  • Creating remote shells (/bin/sh and /bin/csh)
  • Creating cron tasks for persistence
  • Receiving network packets
  • Create a SOCKS reverse proxy for access to internal networks
Sophos XG Firewall

The malware uses TLS encryption for C2 communications and verifies the server certificate against an embedded CA certificate disguised as a certificate from Fortinet. This suggests that the attackers may have originally deployed the backdoor to target FortiGate devices before adapting it for Sophos firewalls.

Researchers observed that while the Pygmy Goat backdoor does not use new techniques, it demonstrates a high level of sophistication in mixing with normal network traffic and responding on demand to attacker commands.

The clean, well-structured code suggests that it was developed by experienced malicious actors. Given the critical role of these devices in network security , the discovery of Pygmy Goat on Sophos XG Firewalls is particularly concerning

See also: Loki: New dangerous backdoor discovered

A backdoor is a method often used in computers to bypass normal authentication procedures, gaining unauthorized access to systems, programs, or devices. Typically, backdoors are created through the use of malware or by exploiting existing vulnerabilities in the software. Once installed, the backdoor allows the person who installed it to access the system covertly, often with complete control. This can lead to data theft, system manipulation, or further malware installation, making backdoors a significant security threat. To address this, strict cybersecurity measures, regular system updates, and comprehensive scanning procedures are necessary to detect and prevent backdoor installations.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS