The Australian government has issued warnings about persistent cyberattacks targeting unpatched Cisco IOS XE devices, specifically exploiting the CVE-2023-20198 vulnerability to deploy the BadCandy webshell. Despite Cisco releasing a patch in October 2023, many devices remain unpatched, allowing attackers to gain root access and reintroduce the webshell even after removal. The Australian Signals Directorate has identified over 400 compromised devices since July 2025, with more than 150 still affected as of late October 2025, and continues to notify victims and provide remediation guidance.
Separately, China-based threat group Storm-1849 (UAT4356) has been actively scanning and exploiting Cisco Adaptive Security Appliances (ASA) used by governments and critical sectors worldwide, including the U.S., Europe, and Asia. Unit 42 researchers observed ongoing targeting of government, defense, and financial institutions throughout October 2025, with federal and local government IP addresses in multiple countries being attacked. These incidents highlight the continued risk posed by unpatched Cisco network devices and the global scale of exploitation by sophisticated threat actors.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said more than 400 devices in Australia had been compromised with the BadCandy web shell via CVE-2023-20198. ASD recommended patching, restricting web UI exposure, removing unauthorized privileged accounts, and monitoring for suspicious configuration changes.
As exploitation of Cisco ASA vulnerabilities continued, CISA issued an emergency directive requiring immediate patching of affected devices. The action followed reports of persistent compromise of government and large-organization firewalls by Storm-1849.
Australia's Signals Directorate warned that attackers were actively exploiting unpatched Cisco IOS XE devices to deploy the Lua-based BadCandy web shell. The agency said operators could detect implant removal and quickly re-exploit unpatched devices, urging immediate patching and hardening.
By late October 2025, at least 150 Cisco IOS XE devices in Australia were reported to be carrying the BadCandy implant after attackers exploited unpatched systems. Reporting described the activity as targeting enterprise and government networks and linked it to Chinese state-backed operations.
Throughout October 2025, Palo Alto Networks Unit 42 observed Storm-1849/UAT4356 scanning for and exploiting Cisco ASA firewalls used by governments, defense contractors, military organizations, and financial institutions in multiple countries. The attackers chained CVE-2025-30333 and CVE-2025-20362 to gain and retain access, including across reboots and upgrades.
In 2024, the ArcaneDoor campaign targeted Cisco ASA devices and was later referenced by researchers as an earlier operation tied to the same nation-state cluster behind the 2025 ASA exploitation activity. This established historical context for later attribution to Storm-1849/UAT4356.
Cisco released fixes for CVE-2023-20198 and CVE-2023-20273, vulnerabilities later cited as the access path used to deploy the BadCandy implant on exposed IOS XE devices. These flaws were subsequently highlighted by defenders as heavily exploited edge-device vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegovinfosecurity.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.