Sophos X-Ops reported a limited series of attacks against Sophos Firewall devices in which attackers exploited CVE-2022-3236 and deployed a sophisticated mix of custom and commodity Linux malware. The intrusions included modifications to legitimate SFOS Java and Perl components, most notably a trojanized servlet-api-3.1.jar that captured administrator credentials, encrypted them, and accepted hidden commands through the JSESSIONID cookie field, creating a covert backdoor on compromised devices.
Investigators identified at least eight malicious file types, including a custom Metasploit JAR, multiple Linux backdoors, a Termite-labeled RAT, and Gh0st RAT variants that used crafted ICMP packets for traffic signaling. The malware enabled file manipulation, shell execution, persistence, encrypted command-and-control, SOCKS proxying, and stealthy communications, indicating a highly capable threat actor focused on maintaining control of firewall appliances while minimizing detection.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Sophos reported that the attackers modified legitimate SFOS Java and Perl components to create covert backdoors, including a trojanized servlet-api-3.1.jar that captured administrator credentials and accepted hidden commands via the JSESSIONID cookie field. The company also identified at least eight malicious file types, including custom backdoors, a Termite-labeled RAT, and Gh0st RAT variants using crafted ICMP packets for covert signaling.
Sophos X-Ops investigated a limited series of attacks against Sophos Firewall devices that began with exploitation of CVE-2022-3236. The intrusions led to deployment of a sophisticated mix of custom and commodity Linux malware on impacted devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.