DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew  Brandt

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew Brandt

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:09

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation reveals a five-year campaign of coordinated attacks targeting firewalls to breach protected networks, with Chinese threat actors exploiting vulnerabilities across multiple phases of attacks 0:17.

Key Takeaways:
• The campaign named "Pacific Rim" involved three phases: initial intrusion in 2018, public mass attacks in 2020, and targeted attacks against specific organizations thereafter 2:43
• Attackers demonstrated sophisticated techniques including rootkits, custom malware, and even repurposed firewalls as operational relay beacons to disguise attack origins 5:30
• Key attacks included "Asnarok" which exploited a SQL injection vulnerability and deployed ransomware called Ragnarok, complete with a "dead man switch" mechanism 9:54
• Sophos responded with "radical transparency," publishing detailed reports and creating an "implant" tool to monitor attacker activity and gather intelligence 3:42
• Threat actors were linked to Chengdu, China, with connections to known APT groups and targeting of organizations supporting oppressed minorities 19:23

These attacks continue today against every major firewall vendor, with vulnerabilities increasing at an alarming rate 30:34.

Sources:

  • 0:17 Introduction to the five-year firewall attack campaign
  • 2:43 Three phases of the Pacific Rim attack campaign
  • 5:30 Cloud snooper attack with rootkit and packet inspection
  • 9:54 Asna

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Let's uh let's give Andrew a big round of applause and welcome him to the Deck on Stage. Hey, thanks. Appreciate you. Have a good time. >> Thank you. Thanks so much. Wow. Uh yeah, not a lot of interest in this talk, I can tell. Um I'm Andrew Brandt. Um firewalls under fire. It's the story of a five-year campaign by threat actors who attack firewalls in order to access the customers and the networks that those firewalls protect. So, this talk is perhaps a little less technical than you might expect from a Defcon talk, but telling the story and its aftermath is a big part of this research, but keep your phone cameras handy. Uh that where there's relevant research and I wrote most of it for Sophos when I was there. Um I've put in QR codes that link to that. So, uh no Rick rolls, I promise. Um…