logo

Arcane Door Reopened: The Cisco Firepower Backdoor That Only a Hard Reboot Can Kill

ID: 04af14ae-1e6c-518f-a3b6-9b1bcf934fcf

STIX ID: report--04af14ae-1e6c-518f-a3b6-9b1bcf934fcf

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

Cisco Talos reports that the threat actor UAT-4356 (associated with the Arcane Door campaign) is actively exploiting critical VPN web server vulnerabilities in Cisco ASA/FTD (notably CVE-2025-20333, CVSS 9.9) to deploy a custom in-memory backdoor called FIRESTARTER. The implant hooks into the LINA process to intercept XML-based WebVPN requests, executing hidden payloads when "magic markers" are present, and achieves persistence by editing the Cisco Service Platform mount list so it reinstalls on graceful reboot (but can be removed by a hard power-cycle). The activity is linked to state-sponsored espionage and demonstrates high sophistication and risk to network infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.