FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
ID: fca54dba-4b6a-5655-adbf-50dc71f7f62d
STIX ID: report--fca54dba-4b6a-5655-adbf-50dc71f7f62d
Feed Name: The Hacker News
CISA and the U.K. NCSC warn that an APT deployed a persistent Linux backdoor called FIRESTARTER on Cisco ASA/FTD devices by exploiting vulnerabilities (notably CVE-2025-20333), enabling remote code execution via a LINA hook and delivery of a post‑exploit toolkit (LINE VIPER); the malware survives firmware updates and normal reboots, necessitating reimaging or cold power cycling to remove, and is tied to broader China‑linked campaigns that leverage compromised SOHO/IoT devices to mask operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
