Asnarök is a custom Linux malware campaign used in 2020 to compromise Sophos XG Firewall appliances after exploitation of a zero-day SQL injection vulnerability that enabled remote code execution. The malware targeted both physical and virtual firewall deployments and was designed primarily for credential and configuration theft from affected edge devices.
The intrusion chain used staged shell scripts and ELF payloads to establish execution, persistence, and data collection on the firewall. Components modified system scripts to survive reboot, downloaded additional binaries, and masqueraded as legitimate firewall processes to reduce suspicion. A dedicated theft module harvested firewall configuration data, device metadata, user and administrator account information, encrypted password material, VPN-related permissions, and network information. Collected data was archived, encrypted, and prepared for upload to attacker-controlled infrastructure, indicating a clear exfiltration objective.
Asnarök is notable as a Linux-targeting threat focused on network security appliances rather than traditional endpoints. Its delivery was tied to direct exploitation of an internet-exposed firewall vulnerability rather than phishing-based access. Public reporting identified the operator as unknown at the time of disclosure. The campaign illustrates the strategic value of edge devices to attackers seeking privileged network visibility, credential access, and durable footholds in enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The Asnarok trojan infection was initiated after the attacker discovered and exploited a zero-day (SQL injection remote code execution) in Sophos XG firewalls. | Vulnerability exploit: attackers will search for exploitable and unpatched publicly faced components in order to access systems. As an example, the attacker behind the NOTROBIN backdoor exploited CVE-2019-19781, a vulnerability in Citrix NetScaler, to spread the malware.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Customized Linux/ELF malware used to compromise Sophos physical and virtual firewalls after exploitation of a zero-day SQL injection RCE vulnerability. It establishes persistence via shell-script modifications, downloads additional ELF payloads, and steals firewall-resident information including user/account data, device details, and password hashes for exfiltration.
Trojan delivered via exploitation of a Sophos XG Firewall zero-day enabling SQL injection and remote code execution.
Named malware/tool referenced in the content without additional description.
Custom malware deployed by Chinese state-sponsored threat actors to maintain persistent remote access and repurpose compromised edge devices as stealthy proxies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.