AquaPurge is a post-compromise log-clearing and log-manipulation utility used to remove evidence of attacker activity from compromised Cisco AsyncOS-based appliances. It has been observed in intrusions attributed to the China-nexus threat actor UAT-9686, deployed alongside other tooling in the Aqua cluster such as AquaShell and AquaTunnel, as well as the tunneling utility Chisel, during exploitation of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager systems.
Its primary function is anti-forensics and defense evasion. AquaPurge selectively removes attacker-related entries or specific keywords from system logs while attempting to leave legitimate activity intact, complicating forensic reconstruction, incident response, and detection. This behavior indicates deliberate efforts to conceal exploitation, persistence, and subsequent operator actions on the appliance.
Observed use places AquaPurge firmly in the post-exploitation phase of the intrusion lifecycle rather than as an initial access payload. In the reported campaigns, attackers first obtained root-level access to exposed Spam Quarantine functionality through exploitation of CVE-2025-20393, then deployed persistence and tunneling components, with AquaPurge used to erase traces of those operations. The malware is associated with espionage-oriented activity targeting internet-exposed edge and email security infrastructure, including organizations in sectors such as telecommunications and critical infrastructure.
AquaPurge is best characterized as a specialized anti-forensics utility rather than a conventional standalone malware family focused on command-and-control or data theft. Its operational value lies in hindering host-based investigation and extending attacker dwell time by reducing visible evidence of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...along with the log-clearing tool AquaPurge.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Log manipulation/cleaning utility used to erase or tamper with logs to hinder detection and forensics.
Log-purging tool used to delete/clear logs on compromised appliances to hinder detection and incident response.
A log-clearing tool used to delete or tamper with logs to reduce forensic visibility and hinder incident response.
A utility used to delete/clean logs on compromised appliances to reduce forensic visibility and hinder incident response.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.