logo

FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches

ID: fca54dba-4b6a-5655-adbf-50dc71f7f62d

STIX ID: report--fca54dba-4b6a-5655-adbf-50dc71f7f62d

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA and the U.K. NCSC warn that an APT deployed a persistent Linux backdoor called FIRESTARTER on Cisco ASA/FTD devices by exploiting vulnerabilities (notably CVE-2025-20333), enabling remote code execution via a LINA hook and delivery of a post‑exploit toolkit (LINE VIPER); the malware survives firmware updates and normal reboots, necessitating reimaging or cold power cycling to remove, and is tied to broader China‑linked campaigns that leverage compromised SOHO/IoT devices to mask operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.