logo

Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies

ID: 4186c073-6d0e-5a17-86ba-faf17a61ed15

STIX ID: report--4186c073-6d0e-5a17-86ba-faf17a61ed15

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-25

...
...

Firestarter, a sophisticated persistent backdoor attributed to state-sponsored actor UAT-4356, has been discovered on Cisco Firepower devices exploiting CVE-2025-20333 and CVE-2025-20362; CISA confirmed infection of a U.S. federal agency device and issued an emergency audit directive. The malware can execute arbitrary code and survive firmware updates and reboots by manipulating the Cisco Service Platform mount list, posing a high risk to government and critical infrastructure networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.