logo

Hackers exploit Cisco SNMP flaw to deploy rootkit on switches

ID: 511e1e82-be98-5acb-94fd-2f3637c5a413

STIX ID: report--511e1e82-be98-5acb-94fd-2f3637c5a413

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-16

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Trend Micro reports 'Operation Zero Disco', an active campaign in which attackers exploited CVE-2025-20352 (an SNMP RCE) in Cisco IOS/IOS XE on 9400, 9300 and legacy 3750G switches to deploy a rootkit that provides a UDP controller/backdoor, disables logging, bypasses AAA and VTY ACLs, hides configuration and enables lateral movement to older Linux hosts lacking EDR; Cisco acknowledged exploitation and researchers published IoCs and recommended low-level firmware/ROM investigation because some components are fileless and disappear on reboot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.