New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices
ID: 067a29ca-86d2-5772-a9fb-9929067c73c0
STIX ID: report--067a29ca-86d2-5772-a9fb-9929067c73c0
Feed Name: HackRead
Threat Score
CISA and the UK NCSC report on FIRESTARTER, a Linux ELF backdoor used by APT actors to maintain persistent C2 on Cisco Firepower and Secure Firewall (ASA/FTD) devices by inline-hooking the LINA engine; attackers exploited CVE-2025-20333 and CVE-2025-20362 and deployed LINE VIPER to establish illegitimate VPN sessions, leaving a sample named 'lina_cs' on compromised devices, with persistence mechanisms that survive firmware updates and reboots unless a hard power cycle is performed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
