Asnarök Trojan
Asnarök is a newly observed trojan targeting Sophos firewall systems affected by the recently disclosed vulnerability CVE-2020-12271.
Summary
Asnarök is a newly observed trojan targeting Sophos firewall systems affected by the recently disclosed vulnerability CVE-2020-12271.
Affected platforms
The following platforms are known to be affected:
- Sophos XG Firewall - All versions
Threat details
Vulnerable devices are first identified using an unknown scanner. When a device is found, an exploit for CVE-2020-122271 is deployed in order to insert a single command containing a delivery URL into a database table. This command is then triggered to download an initial script from a command and control (C2) server and execute it. This script will attempt to alter certain database entries in an effort to disguise itself before modifying an existing script and dropping two additional scripts. These scripts are then used to ensure persistence and allow for data exfiltration.
Once it gains access, Asnarök will attempt to collect information stored on the affected system, including:
- Firewall IP address lists, licence, and serial numbers
- User and administration account email addresses lists
- User's names, usernames, and encrypted passwords
- Salted SHA256 hashes of any administration account passwords
- ID lists for accounts permitted to use the firewall for SSL or clientless VPN connections
This information is then encrypted using Triple DES with the passphrase 'GUCCI' before being sent to a separate C2 address.
Remediation steps
| Type | Step |
|---|---|
|
Sophos has released an update to address CVE-2020-12271, which Asnarök exploits to gain access. Affected organisations are encouraged to review CC-3436 and apply this update immediately. Additionally, to prevent and detect a trojan infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
CVE Vulnerabilities
Last edited: 18 January 2022 8:43 am