NCSC researchers discovered a sophisticated backdoor called “ Pygmy Goat ” that had been deployed on compromised Sophos XG Firewall devices .
See also: North Korean hackers use new VeilShell Backdoor

The malware, discovered by the National Cyber Security Center (NCSC), provides attackers persistent access and powerful capabilities to maintain their foothold in victims' networks.
The Pygmy Goat backdoor is a native x86-32 ELF shared object that leverages the LD_PRELOAD technique to inject itself into the SSH daemon (sshd) process of infected devices. This allows the malware to connect to critical functions and intercept network traffic through the firewall. The backdoor uses multiple methods to establish command and control (C2) communications.
It can monitor incoming ICMP packets for specially crafted messages containing encrypted callback information. In addition, it hooks into the SSH accept function to look for a specific byte sequence in incoming connections, which can be used as an alternative C2 channel.
See also: Spear-phishing campaign infects recruiters with the More_eggs backdoor
Once activated, the Pygmy Goat backdoor provides attackers with a number of capabilities, including:
- Creating remote shells (/bin/sh and /bin/csh)
- Creating cron tasks for persistence
- Receiving network packets
- Create a SOCKS reverse proxy for access to internal networks

The malware uses TLS encryption for C2 communications and verifies the server certificate against an embedded CA certificate disguised as a certificate from Fortinet. This suggests that the attackers may have originally deployed the backdoor to target FortiGate devices before adapting it for Sophos firewalls.
Researchers observed that while the Pygmy Goat backdoor does not use new techniques, it demonstrates a high level of sophistication in mixing with normal network traffic and responding on demand to attacker commands.
The clean, well-structured code suggests that it was developed by experienced malicious actors. Given the critical role of these devices in network security , the discovery of Pygmy Goat on Sophos XG Firewalls is particularly concerning
See also: Loki: New dangerous backdoor discovered
A backdoor is a method often used in computers to bypass normal authentication procedures, gaining unauthorized access to systems, programs, or devices. Typically, backdoors are created through the use of malware or by exploiting existing vulnerabilities in the software. Once installed, the backdoor allows the person who installed it to access the system covertly, often with complete control. This can lead to data theft, system manipulation, or further malware installation, making backdoors a significant security threat. To address this, strict cybersecurity measures, regular system updates, and comprehensive scanning procedures are necessary to detect and prevent backdoor installations.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
