IdentityAuditAction is a custom in-memory web shell/backdoor disguised as a legitimate Cisco Identity Services Engine (ISE) component. According to the provided reporting, it was deployed after successful exploitation of the Cisco ISE zero-day CVE-2025-20337, which enabled pre-authentication remote code execution and administrator/root-level access on affected ISE systems. The malware was described as bespoke and specifically built for Cisco ISE environments rather than commodity malware. Its behavior includes running entirely in memory, using Java reflection for injection into running threads, and registering as an HTTP listener on Tomcat to monitor incoming requests. It was also reported to use DES encryption with non-standard Base64 encoding for evasion, and access required knowledge of specific HTTP headers. The malware was designed to provide silent, persistent control over compromised Cisco ISE appliances while leaving minimal forensic artifacts. Amazon attributed its deployment to an unnamed advanced threat actor that was also exploiting Citrix NetScaler vulnerabilities including CVE-2025-5777 ('CitrixBleed 2') as zero-days. The broader campaign was assessed as indiscriminate internet-wide targeting of critical identity and network access infrastructure, including edge and IAM systems such as Cisco ISE and remote access gateways.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following successful exploitation, the threat actor deployed a custom web shell disguised as a legitimate Cisco ISE component named IdentityAuditAction. This wasn’t typical off-the-shelf malware, but rather a custom-built backdoor specifically designed for Cisco ISE environments.
Following successful exploitation, the threat actor deployed a custom web shell disguised as a legitimate Cisco ISE component named IdentityAuditAction. This wasn’t typical off-the-shelf malware, but rather a custom-built backdoor specifically designed for Cisco ISE environments.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
...implemented DES encryption with non-standard Base64 encoding to evade detection, and required knowledge of specific HTTP headers to access.
...implemented DES encryption with non-standard Base64 encoding to evade detection, and required knowledge of specific HTTP headers to access.
The web shell demonstrated advanced evasion capabilities. It operated completely in-memory, leaving minimal forensic artifacts...
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom-built backdoor web shell specifically designed for Cisco ISE environments. It operates fully in-memory, uses Java reflection for injection, registers an HTTP listener on Tomcat, and employs DES with nonstandard Base64 encoding for access control. It is designed to evade detection and leave minimal artifacts.
A custom in-memory web shell/backdoor designed for Cisco ISE environments. It uses Java reflection to inject into running threads, registers as a listener to monitor HTTP requests across Tomcat, uses DES encryption with non-standard Base64 encoding for evasion, and requires specific HTTP headers for access.
Custom in-memory web shell deployed onto Cisco ISE appliances to provide silent, persistent control while minimizing forensic artifacts; masquerades as a legitimate Cisco ISE component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.