Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
ID: 310d3d56-db20-533c-b03f-996bcffcb409
STIX ID: report--310d3d56-db20-533c-b03f-996bcffcb409
Feed Name: TrendAI Security Blog
Trend Research documents an active campaign (ZeroDisco) exploiting a Cisco SNMP vulnerability (CVE-2025-20352) and a modified Telnet vector to install a rootkit on Cisco switches (notably 9300/9400/3750G). The rootkit implements a universal password, a UDP controller for backdoor management (log deletion, AAA/VTY bypass, hiding config items), and supports lateral movement via ARP spoofing; Trend provides IoCs, detection rules, and vendor collaboration recommendations for investigation and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
