logo

Firestarter malware survives Cisco firewall updates, security patches

ID: fd086420-526e-5b80-a1ba-00ddd4c172d0

STIX ID: report--fd086420-526e-5b80-a1ba-00ddd4c172d0

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Bill Toulas

...
...

Cybersecurity agencies warn of a sophisticated backdoor named Firestarter used by a threat actor Cisco Talos calls UAT-4356 to maintain persistent access on Cisco ASA/FTD devices. The attacker chain included exploiting CVE-2025-20333 and/or CVE-2025-20362, deploying a user-mode loader (Line Viper) to harvest credentials and keys, and installing an ELF implant that hooks into the LINA process to survive reboots, firmware updates, and patches; CISA/NCSC and Cisco published detection YARA rules, IOCs, and remediation guidance including reimaging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.