Andrew Brandt
π€ SpeakerAppearances Over Time
Podcast Appearances
And after we discovered what they were trying to do, the Sophos engineers figured out how to, you know,
changed the firmware on the firewall at that low level so that it wasn't able to run.
And they implemented that in an update.
But that's the scariest thing on all of this.
I think the UEFI bootkit malware on a firewall is the holy grail.
It's where you've got malware on a firewall, it can't be removed.
The firewall has to be thrown in the trash.
And we've already seen that there's been other firewall vendors
where their recommendation was unplug this box and put it in the trash because it is not safe to use anymore.
So it makes me wonder, because we never get the details from other reports about what happened, whether this was successful with other vendors and whether they were testing this with us and it just failed because we were watching them and
stuck a wrench in the works just at the right moment and made it too much of a pain in the butt for them to keep trying.
And they just moved on to the next guy.
one of the actors involved in all of this.
His name is, you know, use the handle GBigMail.
That we eventually figured out his real name.
And the guy appears on the FBI's 10 Most Wanted list today.