CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network
ID: baa60a0a-0aed-5280-b43e-0e0ea8a6b491
STIX ID: report--baa60a0a-0aed-5280-b43e-0e0ea8a6b491
Feed Name: Security Affairs
CISA and the UK NCSC disclosed that an APT deployed the FIRESTARTER Linux ELF backdoor against Cisco Firepower/ASA devices (exploiting CVE-2025-20333 and CVE-2025-20362), enabling persistent remote access that can survive firmware updates and patches by hooking the LINA processing engine and re-establishing itself. The alert details technical behaviours (memory scanning, XML handler detours, persistence mechanisms), correlated use of a post-exploitation implant (LINE VIPER), YARA detection rules, recommended mitigations (reimaging, inventorying devices, patching, account hardening), and directs affected organizations to follow CISA directives and Cisco advisories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
