Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
944 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

This is starting to smell like a nation state actor is behind this.

Darknet Diaries
174: Pacific Rim

Who else has that much time and resources?

Darknet Diaries
174: Pacific Rim

And what the heck was the deal with someone from China submitting this bug the exact same time that Sophos discovered this?

Darknet Diaries
174: Pacific Rim

Chengdu, China again?

Darknet Diaries
174: Pacific Rim

That's where the person who submitted the bug was from.

Darknet Diaries
174: Pacific Rim

So they took this firewall, and again, this one was running a trial license, which was actually just a software-based firewall running in a virtual machine.

Darknet Diaries
174: Pacific Rim

And it's a virtual machine because Sophos isn't allowed to sell their firewalls to China due to export controls.

Darknet Diaries
174: Pacific Rim

So really, nobody in China should even have a Sophos firewall.

Darknet Diaries
174: Pacific Rim

Their suspicion was that the attackers were using this virtual firewall to practice their attacks against, develop them, and then unleash them against the world.

Darknet Diaries
174: Pacific Rim

Because Sophos has the ability to run in a virtual machine with trial licenses, they can just spin one up real quick, try attacks on it.

Darknet Diaries
174: Pacific Rim

If they mess up the firewall, they can just reboot it, take it down, and bring a fresh one up in minutes.

Darknet Diaries
174: Pacific Rim

They looked up who registered that trial license and this gave them an IP address, a username, and an email address.

Darknet Diaries
174: Pacific Rim

And the username was GBigMau.

Darknet Diaries
174: Pacific Rim

So now you pivot on that name.

Darknet Diaries
174: Pacific Rim

What other Sophos products has GBigMao downloaded?

Darknet Diaries
174: Pacific Rim

Then they took a look at his email address and wondered, has this email address been used anywhere else in the world?

Darknet Diaries
174: Pacific Rim

So they do some OSINT investigation to see if this email is known anywhere else.

Darknet Diaries
174: Pacific Rim

That's a nice way to say it.