logo

Don’t take BADCANDY from strangers – How your devices could be implanted and what to do about it

ID: 48a2f56c-fab6-5abf-be54-3033651f786b

STIX ID: report--48a2f56c-fab6-5abf-be54-3033651f786b

Feed Name: Australian Cyber Security Centre (Advisories)

Threat Score
88/100

Date Published: 2025-10-31

Date Updated: 2026-07-26

Author: Australian Cyber Security Centre (ACSC)

...
...

ASD warns that cyber actors are exploiting CVE-2023-20198 in Cisco IOS XE web UI to install a Lua-based web shell named BADCANDY on vulnerable devices; the implant is non-persistent but indicators show ongoing re-exploitation and hundreds of devices in Australia have been compromised between 2023–2025. ASD recommends applying the Cisco patch, rebooting affected devices, reviewing running configurations and accounts, disabling the HTTP server if unused, and following IOS XE hardening guidance to prevent further compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.