Free tools Windows power users keep installed
One-click scans. No signup required.
On December 10, 2024, the U.S. Treasury Department sanctioned Sichuan Silence Information Technology Company Ltd. and its employee Guan Tianfeng over an alleged April 2020 campaign that exploited a zero-day in Sophos firewalls. Treasury said the campaign reached about 81,000 devices worldwide, including more than 23,000 in the United States and 36 protecting U.S. critical-infrastructure companies. The Justice Department separately indicted Guan, while the State Department offered up to $10 million for information.
The public record describes a serious compromise and a narrowly avoided ransomware scenario—not confirmed physical destruction or an oil-rig shutdown. Sophos said it detected and remediated affected customers in approximately two days.
What the United States announced
The actions on December 10, 2024 were coordinated but legally distinct:
- OFAC sanctions: Treasury designated Sichuan Silence and Guan under Executive Order 13694, as amended by Executive Order 13757. The announcement is available at Treasury’s press release.
- Criminal indictment: DOJ charged Guan in federal court in the Northern District of Indiana with conspiracy-related offenses. An indictment is an allegation; it is not a conviction. DOJ’s announcement is at Justice.gov.
- Reward: The State Department’s Rewards for Justice program offered up to $10 million for information about Guan or Sichuan Silence connected to malicious cyber activity against U.S. critical infrastructure. Details are at Rewards for Justice.
The sanctions and indictment do not establish that Guan has been convicted or that he is in U.S. custody.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- XGS 88 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- Equipped with 4 x 2.5 GE copper ports, supporting up to 9.9 Gbps firewall performance for small offices and branch deployments.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Who is involved
| Entity or term | Role in this case |
|---|---|
| Sichuan Silence Information Technology Company Ltd. | Chengdu-based Chinese cybersecurity contractor designated by OFAC. |
| Guan Tianfeng | Chinese security researcher and Sichuan Silence employee sanctioned and indicted by U.S. authorities. |
| Sophos | U.K.-based vendor whose firewall devices were exploited. |
| CVE-2020-12271 / Asnarök | The vulnerability and campaign associated with the April 2020 intrusion. |
| Ragnarok | Ransomware the attackers allegedly attempted to deploy if victims remediated the infection. |
Treasury characterized Sichuan Silence as a government contractor whose clients included PRC intelligence services. It alleged that the company supplied computer-network exploitation, email-monitoring, password-cracking, public-sentiment suppression, and router-probing capabilities. Those are U.S. government allegations and designations, not findings from a completed trial.
What happened between April 22 and 25, 2020
The zero-day exploit
According to DOJ, Guan and alleged co-conspirators used a previously unknown vulnerability in certain Sophos Firewall products. The flaw was later assigned CVE-2020-12271. A zero-day is a vulnerability being exploited before a vendor has had a practical opportunity to provide a fix; it does not mean the flaw remains unpatched forever.
Sophos identified the campaign as Asnarök. Its timeline and broader Pacific Rim reporting are available at Sophos’ timeline and Sophos’ Pacific Rim overview.
Rank #2
- XGS 118 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Scale of the compromise
Treasury said approximately 81,000 firewalls were compromised worldwide, including more than 23,000 in the United States. Thirty-six of the U.S. devices protected critical-infrastructure companies; at least one affected organization was an energy company involved in drilling operations. These figures come from Treasury’s account and are not presented as an independently audited census.
Data theft, followed by a ransomware trap
The initial malware allegedly sought usernames, passwords, and other information from firewalls and connected systems. DOJ said the operators later modified it so that, if a victim tried to remove the malware, it could disable antivirus software and attempt to encrypt computers on the victim’s network with the Ragnarok ransomware variant. The indictment announcement says the encryption efforts did not succeed.
DOJ also said the operators registered domains resembling Sophos-controlled addresses, including sophosfirewallupdate.com, to make the activity appear legitimate.
Rank #3
- Network administrators' main fears are that SSL inspection will have a performance impact or cause something to break, impacting the user experience. Sophos Firewall removes the blind spots caused by encrypted traffic by allowing you to use SSL inspection while maintaining performance efficiency.
- TLS 1.3 Decryption: Remove an enormous blind spot with intelligent TLS inspection that’s fast and effective, supporting the latest standards with extensive exceptions and point-and-click policy tools to make your job easy.
- Deep Packet Inspection: Stop the latest ransomware and breaches with high-performance streaming deep packet inspection, including next-gen IPS, web protection, and app control, as well as deep learning and sandboxing powered by SophosLabs Intelix.
- Sophos Firewall and the XGS Series appliances with dedicated Xstream Flow Processors enable the ultimate in application acceleration, high-performance TLS inspection, and powerful threat protection
- Specifications: Firewall throughput: 35,000 Mbps| Firewall IMIX: 20,000 Mbps | Firewall Latency (64 byte UDP): 4 µs | IPS throughput: 7,000 Mbps | Threat Protection throughput: 1,400 Mbps
Did the attack damage critical infrastructure?
The evidence supports compromise of firewalls protecting critical-infrastructure organizations and a credible risk of further intrusion. It does not publicly establish that an oil rig malfunctioned, that drilling operations stopped, or that physical damage occurred.
Treasury warned that an undetected ransomware deployment could have caused serious injury or loss of life, including through disruption of industrial operations. Sophos detected the intrusion, and DOJ said the company remediated customers’ firewalls in approximately two days. The most accurate description is therefore: the campaign created a potential path to severe operational and physical consequences, but the feared ransomware outcome was detected and thwarted.
Why a firewall compromise matters
A perimeter firewall is more than a traffic filter. It can contain configuration data, administrator credentials, VPN information, and visibility into internal network flows. A compromised appliance may provide:
Rank #4
- XGS 118 with 3 Years Standard Protection - Next-generation firewall appliance with Standard Protection subscription providing firewall, VPN, intrusion prevention, web security, and application control, managed through Sophos Central for unified policies and reporting.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Protects users from ransomware, malware, phishing, and intrusion attempts before they reach endpoints or applications.
- SD-WAN features deliver reliable, optimized application performance and intelligent multi link failover.
- Includes Standard Protection – Comprehensive security package with firewall, intrusion prevention, VPN, web security, and application control to defend against everyday threats and keep business operations safe.
- Access to stored or intercepted usernames and passwords.
- A trusted position from which to reach internal systems.
- A platform for persistence even when endpoint defenses appear healthy.
- A relay point for attacks against other organizations.
Sophos’ broader Pacific Rim investigation describes multiple China-based actors targeting network appliances over several years, including attempts to interfere with telemetry and hotfix mechanisms. That wider reporting supplies context, but it does not prove that every campaign in the investigation was run by Guan or Sichuan Silence.
What the sanctions mean in practice
OFAC sanctions are financial restrictions, not a worldwide criminal ban. In general:
- Property and interests in property of the designated parties in the United States, or in the possession or control of U.S. persons, are blocked.
- U.S. persons generally may not conduct transactions involving the designated parties unless an exemption or OFAC authorization applies.
- Entities owned 50% or more, directly or indirectly, by blocked persons are generally treated as blocked under OFAC’s 50 Percent Rule.
- Financial institutions and other parties that knowingly engage in prohibited transactions can face enforcement or sanctions exposure.
The restrictions primarily affect U.S. persons, U.S.-linked property, and transactions within or transiting the United States. They do not automatically prohibit every person worldwide from dealing with the company, and specific licenses or exemptions can change what is permitted. Organizations should consult current OFAC guidance and qualified counsel before acting.
Best Value
- XGS 128 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, providing up to 19.1 Gbps firewall throughput for larger offices.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
What happened to Guan legally
The DOJ case is an indictment alleging a conspiracy to exploit Sophos firewalls worldwide. Guan is presumed innocent unless the government proves the charges beyond a reasonable doubt. The cited DOJ announcement does not report a conviction, extradition, or arrest in U.S. custody.
Do not confuse this case with other China-related sanctions
| Case | What it concerns |
|---|---|
| Sichuan Silence and Guan (December 2024) | April 2020 Sophos firewall exploitation, Asnarök, CVE-2020-12271, and alleged Ragnarok deployment. |
| Integrity Technology Group (January 2025) | A separate Beijing company and alleged support for the Flax Typhoon group. |
| Salt Typhoon actions | Separate compromises involving telecommunications networks. |
| Sichuan Juxinhe actions | Separate sanctions announced in January 2025. |
Placing these matters under one label such as “China cyber sanctions” can obscure who was accused of what and which victims were affected.
Defensive lessons for organizations
Before an incident
- Keep firewall hardware and software on supported versions and apply vendor hotfixes promptly.
- Restrict administrative interfaces from the public internet and enforce strong, unique administrative credentials.
- Monitor firewall configuration changes, administrator logins, VPN activity, and unusual outbound connections.
- Maintain independent logging because an attacker may try to disable or tamper with vendor telemetry.
- Know how to replace unsupported appliances and preserve configurations securely.
After suspected compromise
- Isolate the appliance according to the vendor’s emergency guidance while preserving forensic evidence.
- Assume credentials exposed through the device may be compromised; rotate administrator, VPN, service-account, and other relevant secrets.
- Review connected systems for new accounts, persistence, lateral movement, ransomware staging, and unexpected remote access.
- Apply the vendor’s fix or rebuild on trusted hardware; do not treat a factory reset alone as proof that an intrusion is gone.
- Coordinate with incident-response specialists, regulators, law enforcement, and critical-infrastructure partners as required.
Sophos specifically recommends following its hardening guidance, enabling hotfixes where supported, monitoring vulnerability notices, and replacing unsupported devices. The episode’s central lesson is broader than one product: a compromised edge device should be handled as a potential network breach, not merely as a defective appliance.
Timeline
| Date | Event |
|---|---|
| December 4, 2018 | Sophos detected an intrusion at the headquarters of its Cyberoam subsidiary during its broader Pacific Rim investigation. |
| April 22–25, 2020 | The Sophos firewall campaign allegedly exploited the vulnerability later designated CVE-2020-12271. |
| April 2020 | Sophos detected and remediated affected customers; the malware was later modified with a ransomware response to remediation. |
| November 2020 onward | Sophos continued documenting related activity and additional vulnerabilities in its wider investigation. |
| October 2024 | Sophos published broader Pacific Rim research on China-based actors targeting network appliances. |
| December 10, 2024 | Treasury sanctioned Sichuan Silence and Guan; DOJ announced the indictment; the State Department announced the reward. |
| February 6, 2025 | The DOJ page indicates its announcement was updated. |
Frequently Asked Questions
Were U.S. oil rigs shut down by this attack?
No public announcement establishes that an oil rig malfunctioned or that physical damage occurred. Treasury described that outcome as a potential consequence of an undetected ransomware deployment; Sophos and DOJ said the intrusion was detected and remediated.
Does an OFAC sanction mean Sichuan Silence is banned everywhere?
No. The designation generally blocks U.S.-linked property and restricts transactions by U.S. persons, subject to exemptions and licenses. It is not automatically a worldwide commercial prohibition.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




