AquaShell is a custom lightweight Python backdoor used to maintain persistence on compromised Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS. It has been associated with exploitation of CVE-2025-20393 by the China-nexus threat actor UAT-9686. The malware is embedded into AsyncOS web components and functions as a passive listener that accepts unauthenticated HTTP POST requests containing encoded commands, which it decodes and executes in the system shell with the privileges obtained through the underlying appliance compromise. This provides a covert command-and-control channel and enables sustained post-compromise access.
Operational reporting links AquaShell to a broader intrusion set that also used reverse-tunneling and anti-forensics tooling, including AquaTunnel, Chisel, and AquaPurge, indicating its role as one component of a persistence and remote-access toolkit for edge-device intrusions. Observed use has centered on a limited subset of internet-exposed appliances with Spam Quarantine enabled under non-standard configurations. The malware’s purpose is persistent backdoor access rather than initial exploitation itself, and its deployment aligns with espionage-oriented operations targeting network edge infrastructure and organizations in sectors such as telecommunications and critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On December 17th, 2025, Cisco published an advisory regarding a zero-day Remote Code Execution (RCE) vulnerability impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, tracked as CVE-2025-20393 (CVSS: 10). | Cisco observed that successful exploitation of the vulnerability resulted in the deployment of the custom webshell AquaShell, a Python-based backdoor capable of receiving and executing encoded commands in the system shell.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco observed that successful exploitation of the vulnerability resulted in the deployment of the custom webshell AquaShell, a Python-based backdoor capable of receiving and executing encoded commands in the system shell.
Cisco observed that successful exploitation of the vulnerability resulted in the deployment of the custom webshell AquaShell, a Python-based backdoor capable of receiving and executing encoded commands in the system shell.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Podľa skupiny Cisco Talos zraniteľnosť zneužíva čínska skupina UAT‑9686 pri nasadzovaní perzistentných zadných dvierok AquaShell...
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lightweight Python backdoor that accepts encoded commands via unauthenticated HTTP POST and executes them in the system shell; linked by Talos to UAT-9686.
Lightweight Python backdoor used post-exploitation to receive and execute base64-encoded commands, enabling flexible C2 on compromised Cisco email security appliances.
Custom-made Python backdoor installed on compromised Cisco Email Security appliances to provide attacker access/persistence.
A custom persistence/backdoor mechanism deployed post-exploitation to maintain long-term access on compromised Cisco Secure Email appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.