Chinese state-linked hacking groups have been actively targeting Cisco network devices, including Adaptive Security Appliance (ASA) firewalls and IOS XE enterprise devices, in a global campaign aimed at government, defense, and corporate networks. Security researchers from Palo Alto Networks’ Unit 42 identified Storm-1849 (also tracked as UAT4356) as responsible for scanning and exploiting Cisco ASA firewalls across the US, Europe, Asia, and other regions, with a particular focus on high-value targets such as federal agencies, financial institutions, and defense contractors. The campaign, observed throughout October, included a notable pause during China’s Golden Week holiday, and targeted public network addresses in countries including India, Nigeria, Japan, France, the UK, and Australia.
In Australia, the national cyber defense agency reported that at least 150 Cisco IOS XE devices were compromised with the "BadCandy" web shell implant, which is deployed by exploiting zero-day vulnerabilities CVE-2023-20198 and CVE-2023-20273. These vulnerabilities, which do not require authentication to exploit, allow attackers to create local administrator accounts and maintain access even after device reboots. The BadCandy implant, attributed to Chinese nation-state actors such as Salt Typhoon, is part of a broader trend of targeting network edge devices to establish persistent access within sensitive networks. The Five Eyes intelligence alliance has highlighted these vulnerabilities as among the most exploited by nation-state actors in 2023.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
By late October 2025, at least 150 Cisco IOS XE devices in Australia were found carrying the BadCandy web shell implant. The activity was attributed to the Chinese state-linked group Salt Typhoon, which used the previously patched CVE-2023-20198 and CVE-2023-20273 flaws to establish access to enterprise and government networks.
In October 2025, Palo Alto Networks Unit 42 observed Storm-1849, also tracked as UAT4356, targeting Cisco ASA firewalls used by governments and large organizations across the United States, Europe, Asia, Africa, and the Middle East. The campaign chained CVE-2025-30333 and CVE-2025-20362 to gain deep, persistent access that could survive reboots and upgrades.
CISA issued an emergency directive requiring U.S. federal civilian agencies to patch Cisco ASA vulnerabilities CVE-2025-30333 and CVE-2025-20362. The directive reflected concern that the flaws were being actively exploited against high-value targets.
The Australian Cyber Security Centre and Five Eyes partners identified the Cisco IOS XE vulnerabilities CVE-2023-20198 and CVE-2023-20273 as among the most exploited flaws in 2023. Their guidance emphasized patching and reducing internet exposure of Cisco web interfaces.
Cisco released patches for the IOS XE vulnerabilities CVE-2023-20198 and CVE-2023-20273, which can let unauthenticated attackers create local administrator accounts on exposed devices. These flaws were later cited by defenders as among the most exploited vulnerabilities of 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.