US sanctions Chinese cybersecurity firm for firewall hacks targeting critical infrastructure

US sanctions Chinese cybersecurity firm for firewall hacks targeting critical infrastructure
By: technology Posted On: December 10, 2024 View:

The U.S. sanctioned a Chinese cybersecurity company and one of its employees for exploiting a zero-day vulnerability in Sophos firewalls to target U.S. organizations.

On Tuesday, the U.S. Treasury Department said Guan Tianfeng, an employee of Sichuan Silence, used the vulnerability to compromise approximately 81,000 firewalls in April 2020. The hacking campaign, detailed by Sophos in November, led to the compromise of more than 23,000 firewalls in the U.S., dozens of which were used at a government agency, and critical infrastructure companies. 

One of these was an energy company involved in drilling operations. The Treasury noted that the incident could have caused “significant loss in human life” if the attack had been successful. 

“The purpose of the exploit was to use the compromised firewalls to steal data,” the Treasury said. “However, Guan also attempted to infect the victims’ systems with the Ragnarok ransomware variant.”

Read this on technology



Header Banner



Note: There may be some affiliate / associate links throughout the pages of this site. By buying through the links we may receive a commission for the sale. This has no effect on the price you pay.
  Contact Us
  • We would love to hear from you
  • infobuxx@allsites.zendesk.com
  Follow Us
Site Map
Get Site Map
  About

Infobuxx: Your go-to source for the latest in entertainment, health, business, politics, sports, movies, economics, and trending news. Stay informed and entertained with updates that matter!