IdentityAuditAction is a bespoke web shell/backdoor deployed on compromised Cisco Identity Services Engine (ISE) systems. It was observed in intrusions exploiting the Cisco ISE zero-day CVE-2025-20337, and reporting also linked the broader threat activity to exploitation of Citrix NetScaler ADC CVE-2025-5777 (Citrix Bleed Two). The malware was disguised as a legitimate Cisco ISE component named IdentityAuditAction and was tailored specifically for Cisco ISE environments rather than being an off-the-shelf tool. Its implementation ran fully in memory, was injected via Java reflection, and registered an HTTP listener on Tomcat. Reported functionality and tradecraft include use of DES with nonstandard Base64 encoding, a deserialization routine that decoded a payload, instantiated a proxy class, and executed it, and access controls requiring specific HTTP headers. It was designed to leave minimal forensic artifacts. The activity was attributed by Amazon threat intelligence to an advanced, well-funded threat actor with deep knowledge of Java, Tomcat, and Cisco ISE internals, and the targeting context included enterprise identity infrastructure and critical infrastructure environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom in-memory web shell/backdoor designed for Cisco ISE environments, deployed by an APT group after exploiting zero-day vulnerabilities. It uses Java reflection, registers as an HTTP listener on Tomcat, encrypts communications with DES and non-standard Base64, and requires specific HTTP headers for access.
A custom-built backdoor web shell specifically designed for Cisco ISE environments. It operates fully in-memory, is injected via Java reflection, and registers an HTTP listener on Tomcat. It uses DES with nonstandard Base64 encoding, requires specific headers for access, and leaves minimal artifacts, indicating a highly sophisticated and stealthy design.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.