logo

UAT-4356's Targeting of Cisco Firepower Devices

ID: a9dc2cd8-20ac-5b97-88c2-aab129c1a838

STIX ID: report--a9dc2cd8-20ac-5b97-88c2-aab129c1a838

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos documents active, state-linked exploitation of n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Firepower FXOS appliances by actor UAT-4356 to install the FIRESTARTER backdoor. The report details FIRESTARTER's persistence method, injection of stage shellcode into the LINA process, XML-based activation, IOCs (filenames and commands), and recommended mitigations including vendor patches, device reimaging, and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.