Arcane Door Reopened: The Cisco Firepower Backdoor That Only a Hard Reboot Can Kill
ID: 04af14ae-1e6c-518f-a3b6-9b1bcf934fcf
STIX ID: report--04af14ae-1e6c-518f-a3b6-9b1bcf934fcf
Feed Name: securityonline.info
Cisco Talos reports that the threat actor UAT-4356 (associated with the Arcane Door campaign) is actively exploiting critical VPN web server vulnerabilities in Cisco ASA/FTD (notably CVE-2025-20333, CVSS 9.9) to deploy a custom in-memory backdoor called FIRESTARTER. The implant hooks into the LINA process to intercept XML-based WebVPN requests, executing hidden payloads when "magic markers" are present, and achieves persistence by editing the Cisco Service Platform mount list so it reinstalls on graceful reboot (but can be removed by a hard power-cycle). The activity is linked to state-sponsored espionage and demonstrates high sophistication and risk to network infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
