Firestarter malware survives Cisco firewall updates, security patches
ID: fd086420-526e-5b80-a1ba-00ddd4c172d0
STIX ID: report--fd086420-526e-5b80-a1ba-00ddd4c172d0
Feed Name: Bleeping Computer
Cybersecurity agencies warn of a sophisticated backdoor named Firestarter used by a threat actor Cisco Talos calls UAT-4356 to maintain persistent access on Cisco ASA/FTD devices. The attacker chain included exploiting CVE-2025-20333 and/or CVE-2025-20362, deploying a user-mode loader (Line Viper) to harvest credentials and keys, and installing an ELF implant that hooks into the LINA process to survive reboots, firmware updates, and patches; CISA/NCSC and Cisco published detection YARA rules, IOCs, and remediation guidance including reimaging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
