Don’t take BADCANDY from strangers – How your devices could be implanted and what to do about it
ID: 48a2f56c-fab6-5abf-be54-3033651f786b
STIX ID: report--48a2f56c-fab6-5abf-be54-3033651f786b
Date Published: 2025-10-31
Date Updated: 2026-07-26
Author: Australian Cyber Security Centre (ACSC)
ASD warns that cyber actors are exploiting CVE-2023-20198 in Cisco IOS XE web UI to install a Lua-based web shell named BADCANDY on vulnerable devices; the implant is non-persistent but indicators show ongoing re-exploitation and hundreds of devices in Australia have been compromised between 2023–2025. ASD recommends applying the Cisco patch, rebooting affected devices, reviewing running configurations and accounts, disabling the HTTP server if unused, and following IOS XE hardening guidance to prevent further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
