TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 (T1203). The actor exhibited odd telemetry behavior indicative of intermittent VPN usage, switching between IP addresses geolocated to Hong Kong and Chengdu. Analysis revealed malware samples for Mac OS X and iOS, as well as IFRAME injection code exploiting a WebAssembly vulnerability (T1189). Additionally, TStark was linked to the development of libsophos.so and the deployment of malicious payloads across their devices.
Which appliance vulnerability is primarily targeted by the Tstark threat actor?+
The Tstark threat actor primarily exploits CVE-2020-15069 found on Sophos firewall appliances.
What indicators should defenders monitor for to detect suspicious activity related to Tstark?+
Defenders should monitor for unauthorized software changes on Sophos devices, anomalous VPN connections from unusual geolocations (specifically IPs switching between Hong Kong and Chengdu), and the presence of the libsophos.so file.