174: Pacific Rim
May 5, 2026
Summary
Sophos researchers Andrew Brandt and Craig Jones investigate a sophisticated attack where hackers stole source code from a 2018 breach to exploit an SQL injection vulnerability in Sophos firewalls. This allowed attackers to redirect 80,000 devices to malicious update servers, prompting Sophos to deploy emergency hotfixes and secret kernel implants to spy on the threat actors' lab in China. The episode explores the ethical dilemmas of these defensive measures and Sophos's unprecedented transparency in exposing the nation-state-level campaign.
Topics discussed
Introduction and the initial TV set infection
Sponsors: ThreatLocker and Meter
The Cyberome source code theft and early intrusions
Discovery of the SQL injection vulnerability in Sophos firewalls
The massive 80,000 firewall compromise and hotfix debate
Sophos' decision to deploy a silent hotfix and public disclosure
Investigating the attacker: GBIGMAU and Chinese origins
Deploying a kernel implant to spy on the attackers' lab
Seizing C2 servers and identifying the Ragnarok campaign
Sponsor: Drada
Round Two: The Pacific Rim campaign and new exploits
Attribution to Chinese state actors and Uyghur surveillance
The escalating arms race and zero-day vulnerabilities
Targeting critical infrastructure and the limits of defense
Advanced malware: UEFI persistence and firmware attacks
Conclusion: The ongoing threat and industry challenges
Listen ad-free on Castria