Live
eineurope/
Home/United States/Topic · CISA: FIRESTARTER backdoor persists on federal Cisco ASA
United States3d ago

CISA: FIRESTARTER backdoor persists on federal Cisco ASA

A state-sponsored actor is exploiting patched Cisco Firepower vulnerabilities to deploy the FIRESTARTER backdoor malware.

Sources
5 verified
Location
Updated
Saturday, 25 April 2026 at 05:00 UTC
No media · text-only dispatch
Synthesis · 5 sources
A state-sponsored threat actor tracked as UAT-4356 is actively exploiting two patched vulnerabilities in Cisco Firepower FXOS devices (CVE-2025-20333, CVE-2025-20362) to deploy a custom backdoor called FIRESTARTER. The malware injects shellcode into the LINA process and replaces a legitimate WebVPN handler, enabling silent command execution while forwarding normal traffic to evade detection. Cisco Talos has identified indicators of compromise, including suspicious files at /usr/bin/lina_cs and a specific ClamAV signature. The implant persists through graceful reboots but not hard power cycles, and organizations are urged to apply patches immediately or reimage affected systems for complete remediation.
Updates · 4
3d ago🇬🇧 SITREP - Independent OSINT Channel 🇬🇧

The UK's National Cyber Security Centre (NCSC) has joined the US CISA in issuing the warning, and the actor is identified as UAT-4356.

3d ago🇬🇧 SITREP - Independent OSINT Channel 🇬🇧

New details confirm the backdoor was found on a specific federal agency's Cisco Firepower appliance and emphasize the persistence gap in perimeter device security.

3d ago🇬🇧 SITREP - Independent OSINT Channel 🇬🇧

The joint advisory adds that the UK NCSC is also involved and that the backdoor's update-resistant persistence mechanism represents an elevated capability, prompting a sector-wide alert.

3d ago🇬🇧 SITREP - Independent OSINT Channel 🇬🇧

Cisco Talos has identified the specific threat actor (UAT-4356) and the two patched vulnerabilities (CVE-2025-20333, CVE-2025-20362) being exploited, along with technical details of the FIRESTARTER malware's persistence and detection signatures.

e/eineurope · topic · T-06531