Desk live·
ForensicPost
Nation-state/Infrastructure/File 24-1031

Sophos Published Five Years of Attacks on Its Own Firewalls and Its Use of an Implant

Sophos published five years of intrusions against its own firewalls in October 2024 — and disclosed that in 2020, after taking legal advice, it deployed a targeted implant onto attacker-controlled devices to watch what they did next.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomAbingdonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSophos perimeter devices
ActorChina-based groups, per the vendor
S. Rosler13 min readConfidence: medium2 sources reviewed

On 31 October 2024 Sophos published Pacific Rim, an account of a campaign it says ran from December 2018 to March 2024 against its own perimeter products — XG firewalls and legacy Cyberoam appliances — and against internet-facing user and administrative portals. Named vulnerabilities include CVE-2020-12271, tracked as Asnarök, CVE-2020-15069, CVE-2020-29574, CVE-2022-1040 and CVE-2022-3236.

Sophos attributes the activity to China-based groups. It notes that France’s ANSSI attributed attacks involving Cyberoam appliances to APT-31. The account also states that in 2020, after consulting legal counsel, the company deployed a targeted implant onto attacker-controlled devices — dated to 9 July 2020 — which gave it what it describes as near-real-time observability, and which by 27 July had revealed a previously unknown zero-day.

A Vendor Publishing Against Its Own Interest

This desk is cautious with vendor research, and says so in the sourcing note at 25-0421b: a caseload is not a population, and a company documenting the threat it sells against has an interest in the finding.

Neither objection has much force here. The product being defeated is the vendor’s own, repeatedly, over five years, with the CVE numbers printed. Whatever else Pacific Rim is, it is not marketing, and we have recorded it as the strongest form of vendor disclosure available: the kind that costs the publisher something.

The Implant Is The Part Without A Precedent

A private company placed monitoring code on devices it did not own, controlled by people it was investigating, and has said so in public.

We have no other file in which a defender does this. It records law enforcement seizing infrastructure at 23-0404 and 26-0707, and it records a vendor counter-exploiting an attacker’s position to recover funds at 22-0202 — but that was a recovery, after the fact, of the vendor’s own money. This is surveillance, conducted by a corporation, for intelligence.

What "After Consulting Legal Counsel" Establishes

The phrase is the company’s own, and it establishes that Sophos asked. It does not establish that the answer generalises.

The desk records the question rather than an answer, because the question is the interesting part: there is no published standard for when a private party may instrument a machine it does not own, the answer plainly varies by jurisdiction, and a vendor with the capability to do this has it whether or not a rule exists. We filed adjacent boundary problems at 22-0627, where an attacker argued proportionality, and at 22-1218.

Five Years On The Same Class Of Device

Strip the unusual elements and what remains is the pattern we have recorded more than any other: the edge device as the way in, repeatedly, for years.

It files Citrix appliances at 23-1010, an email security gateway at 23-0518 where the vendor told customers to replace the hardware rather than patch it, satellite modems at 22-0224 and Ivanti at 23-0724. Pacific Rim adds the longitudinal view: one product line, one adversary set, five years, five CVEs. The device that terminates the perimeter is the device on the perimeter.

How we reported this

Compiled from Sophos X-Ops’ published Pacific Rim material, listed below. This is a single-source account by an interested party about its own products and its own actions, and no independent corroboration of the implant deployment or its legal basis was available to this desk — which is why the file is graded medium despite the detail. The APT-31 attribution is ANSSI’s, reported by Sophos; this desk attributes nothing to any state. No indicators are reproduced. Corrections: corrections@forensicpost.com.

Sources
  1. Pacific Rim: timelineSophos
  2. Pacific Rim — Sophos X-OpsSophos
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary