Unknown attackers exploited a zero-day SQL injection flaw in certain Sophos firewall products to gain remote code execution and deploy the Asnarök malware, using staged shell scripts and ELF binaries to persist on both physical and virtual appliances while masquerading as legitimate processes. The intrusion chain initially focused on stealing firewall configuration data plus user and administrator credentials, and Sophos later said multiple targeted firewalls showed network activity to the exfiltration server 38.27.99.69. The company issued hotfixes, blocked related infrastructure, and added detections for the malware as Linux/Agnt-G.
Sophos later reported that the same operators changed the attack while it was underway after defenses were introduced, activating a backup channel and replacing the earlier 2own theft component with a Linux ELF payload intended to spread Ragnarok ransomware into internal Windows environments. The payload enumerated hosts through the firewall ARP cache, scanned SMB on port 445, and attempted to use EternalBlue and DoublePulsar to inject DLLs into explorer.exe on vulnerable older Windows 7 systems, which then used certutil.exe to fetch ransomware from attacker-controlled infrastructure on port 81. Sophos said its hotfixes blocked the SQL injection vector, removed malicious components without requiring a reboot, and disrupted the later ransomware-delivery stage.

See which actors are running it and whether you're in range.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.