Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
ID: 511e1e82-be98-5acb-94fd-2f3637c5a413
STIX ID: report--511e1e82-be98-5acb-94fd-2f3637c5a413
Feed Name: Bleeping Computer
Trend Micro reports 'Operation Zero Disco', an active campaign in which attackers exploited CVE-2025-20352 (an SNMP RCE) in Cisco IOS/IOS XE on 9400, 9300 and legacy 3750G switches to deploy a rootkit that provides a UDP controller/backdoor, disables logging, bypasses AAA and VTY ACLs, hides configuration and enables lateral movement to older Linux hosts lacking EDR; Cisco acknowledged exploitation and researchers published IoCs and recommended low-level firmware/ROM investigation because some components are fileless and disappear on reboot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
