logo

New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices

ID: 067a29ca-86d2-5772-a9fb-9929067c73c0

STIX ID: report--067a29ca-86d2-5772-a9fb-9929067c73c0

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Deeba Ahmed

...
...

CISA and the UK NCSC report on FIRESTARTER, a Linux ELF backdoor used by APT actors to maintain persistent C2 on Cisco Firepower and Secure Firewall (ASA/FTD) devices by inline-hooking the LINA engine; attackers exploited CVE-2025-20333 and CVE-2025-20362 and deployed LINE VIPER to establish illegitimate VPN sessions, leaving a sample named 'lina_cs' on compromised devices, with persistence mechanisms that survive firmware updates and reboots unless a hard power cycle is performed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.