Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
perimeter-device-exposuregovernment-diplomatic-threatstate-sponsored-espionageremote-access-implant

Firestarter Backdoor Persists on Cisco Firewalls After Patching

Updated 2mo agoFirst seen Apr 25, 202610 sources

U.S. and U.K. cybersecurity agencies warned that a previously undisclosed backdoor dubbed Firestarter compromised at least one unnamed U.S. Federal Civilian Executive Branch agency and may be part of a broader campaign targeting government and critical national infrastructure networks. The malware affects Cisco Secure Firewall devices running ASA or FTD software, and Cisco Talos linked the activity to threat cluster UAT-4356, which is assessed as likely government-backed. Investigators said the actor likely gained initial access by exploiting CVE-2025-20333 and/or CVE-2025-20362, then deployed the Line Viper shellcode loader before installing Firestarter.

Firestarter is notable for maintaining persistence even after reboots, firmware upgrades, and security patches by hooking into Cisco’s LINA process, altering boot and mount behavior, and relaunching if terminated. CISA, the UK NCSC, and Cisco published indicators of compromise, YARA-based memory analysis guidance, and mitigation advice, warning that software updates alone may not remove the implant. Cisco strongly recommended reimaging affected devices and upgrading to fixed releases, while authorities urged organizations to collect forensic evidence and report suspected compromises.

Share:
Firestarter Backdoor Persists on Cisco Firewalls After Patching
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 25, 20262mo ago

Samsung MagicINFO and D-Link DIR-823X flaws tied to Mirai activity

Active exploitation was also identified for Samsung MagicINFO 9 Server flaw CVE-2024-7399 and D-Link DIR-823X command injection flaw CVE-2025-29635. Reporting cited in the coverage linked both vulnerabilities to Mirai botnet activity.

SimpleHelp vulnerabilities used as precursors to ransomware attacks

Reporting cited by CISA indicated that the SimpleHelp flaws CVE-2024-57726 and CVE-2024-57728 had already been actively exploited, including as precursors to ransomware intrusions attributed to DragonForce. The two bugs can be chained to escalate privileges and achieve full server compromise.

Apr 24, 20262mo ago

CISA sets May 8 deadline for federal remediation or device removal

CISA directed Federal Civilian Executive Branch agencies to remediate the newly listed KEV vulnerabilities by May 8, 2026, and advised discontinuing use of the end-of-life D-Link DIR-823X if it could not be secured. The agency also urged organizations to apply vendor fixes, monitor for suspicious activity, and disconnect vulnerable SimpleHelp systems if mitigations were unavailable.

CISA adds four actively exploited flaws to the KEV catalog

On April 24, 2026, CISA added CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9 Server, and CVE-2025-29635 in D-Link DIR-823X routers to its Known Exploited Vulnerabilities catalog. The agency cited evidence of active exploitation for all four vulnerabilities.

Cisco and CISA publish Firestarter mitigations and detection guidance

Alongside the Firestarter disclosure, Cisco and CISA released indicators of compromise, YARA-based detection guidance, and mitigation advice. Cisco strongly recommended reimaging affected devices and upgrading to fixed releases because the malware can survive reboots, updates, and patches.

CISA and NCSC disclose Firestarter malware campaign

On April 24, 2026, CISA and the U.K. NCSC publicly warned about the previously unknown Firestarter backdoor affecting Cisco ASA and FTD devices and said it had compromised at least one unnamed U.S. federal agency. The agencies assessed the activity could be part of a broader campaign targeting government and critical national infrastructure networks.

Cisco flaws exploited to breach a U.S. federal agency firewall

In an incident investigated by CISA and partners, a threat actor later tracked as UAT-4356 gained initial access to a U.S. Federal Civilian Executive Branch agency by exploiting CVE-2025-20333 and/or CVE-2025-20362 on a Cisco Firepower device running ASA software. The actor deployed the Line Viper shellcode loader and then installed the Firestarter backdoor.

Mar 31, 20263mo ago

Firestarter access persisted through March 2026 despite patching

In the federal civilian agency intrusion, attackers retained or regained access to the compromised Cisco ASA/FTD device through March 2026 even after patches were deployed. The case showed roughly six months of dwell time and demonstrated that Firestarter persistence could survive normal remediation short of hard power cycling or full reimaging.

Uncovering FIRESTARTER: Ongoing Cisco ASA Compromise Despite Patch Deployment | by Criminal IP | May, 2026 | OSINT Team
Mar 2, 20264mo ago

Microsoft links ArcaneDoor activity to Storm-1849

Coverage of the Firestarter/ArcaneDoor campaign said Cisco Talos attributed the activity to UAT-4356 and that Microsoft tracks the same China-nexus actor as Storm-1849. This added a new attribution detail to the campaign affecting Cisco ASA and FTD devices.

Cisco firewalls at risk from Firestarter bug: CISA - SDxCentral
Sep 30, 20259mo ago

Firestarter implant deployed on federal Cisco device by late September 2025

CISA said attackers had installed the Firestarter backdoor on a Cisco security appliance protecting a U.S. federal civilian agency before the end of September 2025. The intrusion also involved the Line Viper shellcode loader, with Firestarter used to maintain persistent access.

CISA Hunts for Cisco Backdoor Spotted on Federal Network
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Firestarter Backdoor Persists on Cisco Firewalls After Patching | Mallory