Darknet Diaries Darknet Diaries

174: Pacific Rim

May 5, 2026

Summary

Sophos researchers Andrew Brandt and Craig Jones investigate a sophisticated attack where hackers stole source code from a 2018 breach to exploit an SQL injection vulnerability in Sophos firewalls. This allowed attackers to redirect 80,000 devices to malicious update servers, prompting Sophos to deploy emergency hotfixes and secret kernel implants to spy on the threat actors' lab in China. The episode explores the ethical dilemmas of these defensive measures and Sophos's unprecedented transparency in exposing the nation-state-level campaign.

Topics discussed

Introduction and the initial TV set infection Sponsors: ThreatLocker and Meter The Cyberome source code theft and early intrusions Discovery of the SQL injection vulnerability in Sophos firewalls The massive 80,000 firewall compromise and hotfix debate Sophos' decision to deploy a silent hotfix and public disclosure Investigating the attacker: GBIGMAU and Chinese origins Deploying a kernel implant to spy on the attackers' lab Seizing C2 servers and identifying the Ragnarok campaign Sponsor: Drada Round Two: The Pacific Rim campaign and new exploits Attribution to Chinese state actors and Uyghur surveillance The escalating arms race and zero-day vulnerabilities Targeting critical infrastructure and the limits of defense Advanced malware: UEFI persistence and firmware attacks Conclusion: The ongoing threat and industry challenges
Listen ad-free on Castria