RayInitiator is a persistent multi-stage GRUB bootkit used to compromise Cisco ASA 5500-X Series devices that lack Secure Boot. It is associated with the threat activity linked to the ArcaneDoor cluster and has been used to establish durable access on exposed Cisco perimeter appliances, particularly in targeted espionage operations against government networks. The malware is flashed into the device boot chain and survives normal reboots and firmware upgrades, giving operators a long-lived foothold below the operating system level.
Its architecture is staged. Early stages modify GRUB and subsequent boot components, while later stages patch kernel and user-space execution paths to install a handler inside the ASA lina process. RayInitiator’s later-stage logic hooks WebVPN XML parsing so that specially crafted authentication traffic can trigger in-memory execution of additional payloads. Its primary known role is to deploy LINE VIPER, a user-mode shellcode loader, directly into device memory. This deployment path uses victim-specific values and memory-permission changes to execute staged shellcode while minimizing persistent user-space artifacts.
RayInitiator provides persistence and post-exploitation enablement rather than broad standalone operator functionality. By embedding itself in the boot process and modifying runtime behavior in lina, it enables follow-on capabilities delivered through LINE VIPER, including privileged command execution, packet capture, VPN authentication bypass, log suppression, and anti-forensic actions. Reporting on later related tooling has identified substantial technical overlap between RayInitiator’s stage-3 deployment mechanism and the FIRESTARTER implant, suggesting a shared development lineage or common operator tradecraft.
Observed deployment has been tied to exploitation of Cisco ASA and FTD WebVPN vulnerabilities disclosed in 2025, with attacks concentrated on ASA 5500-X hardware that does not implement Secure Boot or Trust Anchor protections. The malware is notable for targeting end-of-support or legacy edge security appliances where compromise of the boot chain can persist across routine administrative recovery actions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On September 25, Cisco published two critical advisories regarding CVE-2025-20333 (CVSS 9.9) and CVE-2025-20363 (CVSS 9.0). The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests. The vulnerabilities affect Cisco Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), and IOS. A successful exploitation may lead to complete compromise of the affected device. Active exploitation of these vulnerabilities in targeted attacks has been confirmed. | The UK National Cyber Security centre (NCSC-UK) has published a new analysis of the malware components, dubbed RayInitiator and LINE VIPER, to assist with detection and mitigation.
On September 25, Cisco published two critical advisories regarding CVE-2025-20333 (CVSS 9.9) and CVE-2025-20363 (CVSS 9.0). The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests. The vulnerabilities affect Cisco Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), and IOS. A successful exploitation may lead to complete compromise of the affected device. Active exploitation of these vulnerabilities in targeted attacks has been confirmed. | The UK National Cyber Security centre (NCSC-UK) has published a new analysis of the malware components, dubbed RayInitiator and LINE VIPER, to assist with detection and mitigation.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication. | On September 25th, 2025, the UK's NCSC published a malware analysis report that provided detailed insights into RayInitiator, a persistent, multi-stage bootkit. This bootkit facilitates the deployment of LINE VIPER, a user-mode shellcode loader, on Cisco ASA 5500-X Series lacking secure boot.
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The UK National Cyber Security centre (NCSC-UK) has published a new analysis of the malware components, dubbed RayInitiator and LINE VIPER, to assist with detection and mitigation.
Cisco Talos noted that Firestarter shares significant technical similarities with a previously documented implant called RayInitiator, suggesting the tools share a common origin or development history within UAT-4356’s arsenal.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers successfully exploited these vulnerable devices to deploy malware, execute remote commands, and potentially exfiltrate data.
The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests.
On September 25th, 2025, the UK's NCSC published a malware analysis report that provided detailed insights into RayInitiator, a persistent, multi-stage bootkit.
Cisco's investigation uncovered a sophisticated attack that employed advanced evasion techniques, including disabling logging, intercepting CLI commands, and deliberately crashing devices to thwart diagnostic analysis.
LINE VIPER and RayInitiator utilise victim specific tokens... To check for a LINE VIPER request, the <group-select> element is verified to ensure it starts with a hard-coded, victim specific, 8-byte ASCII string... LINE VIPER tasking payloads sent to victim devices are checked for multiple victim-specific tokens before they are run.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously disclosed bootkit noted as technically similar to FIRESTARTER.
Referenced as a malware/tool whose deployment tactics substantially overlap with FIRESTARTER’s loading mechanism.
A previously documented bootkit noted only as having overlap with FIRESTARTER.
A previously documented implant that shares significant technical similarities with Firestarter, suggesting common origin or development history within UAT-4356’s toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.