Tstark is a threat actor exploiting CVE-2020-15069 on Sophos firewall appliances.
Analyst brief
Tstark is a threat actor identified by X-Ops, primarily exploiting CVE-2020-15069 on Sophos firewall appliances. The actor obfuscates activity via intermittent VPN usage, switching between IPs geolocated to Hong Kong and Chengdu. Their TTPs include bookmark buffer overflow (T1203), IFRAME injection exploiting a WebAssembly vulnerability (T1189), and deployment of the malicious library libsophos.so. Defenders should monitor for unauthorized software changes on Sophos devices, anomalous VPN connections from unusual geolocations, and the presence of libsophos.so.
Tstark
unknown
TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 (T1203). The actor exhibited odd telemetry behavior indicative of intermittent VPN usage, switching between IP addresses geolocated to Hong Kong and Chengdu. Analysis revealed malware samples for Mac OS X and iOS, as well as IFRAME injection code exploiting a WebAssembly vulnerability (T1189). Additionally, TStark was linked to the development of libsophos.so and the deployment of malicious payloads across their devices.
Which appliance vulnerability is primarily targeted by the Tstark threat actor?+
The Tstark threat actor primarily exploits CVE-2020-15069 found on Sophos firewall appliances.
What indicators should defenders monitor for to detect suspicious activity related to Tstark?+
Defenders should monitor for unauthorized software changes on Sophos devices, anomalous VPN connections from unusual geolocations (specifically IPs switching between Hong Kong and Chengdu), and the presence of the libsophos.so file.