U.S. and U.K. cybersecurity agencies warned that a previously undisclosed backdoor dubbed Firestarter compromised at least one unnamed U.S. Federal Civilian Executive Branch agency and may be part of a broader campaign targeting government and critical national infrastructure networks. The malware affects Cisco Secure Firewall devices running ASA or FTD software, and Cisco Talos linked the activity to threat cluster UAT-4356, which is assessed as likely government-backed. Investigators said the actor likely gained initial access by exploiting CVE-2025-20333 and/or CVE-2025-20362, then deployed the Line Viper shellcode loader before installing Firestarter.
Firestarter is notable for maintaining persistence even after reboots, firmware upgrades, and security patches by hooking into Cisco’s LINA process, altering boot and mount behavior, and relaunching if terminated. CISA, the UK NCSC, and Cisco published indicators of compromise, YARA-based memory analysis guidance, and mitigation advice, warning that software updates alone may not remove the implant. Cisco strongly recommended reimaging affected devices and upgrading to fixed releases, while authorities urged organizations to collect forensic evidence and report suspected compromises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Active exploitation was also identified for Samsung MagicINFO 9 Server flaw CVE-2024-7399 and D-Link DIR-823X command injection flaw CVE-2025-29635. Reporting cited in the coverage linked both vulnerabilities to Mirai botnet activity.
Reporting cited by CISA indicated that the SimpleHelp flaws CVE-2024-57726 and CVE-2024-57728 had already been actively exploited, including as precursors to ransomware intrusions attributed to DragonForce. The two bugs can be chained to escalate privileges and achieve full server compromise.
CISA directed Federal Civilian Executive Branch agencies to remediate the newly listed KEV vulnerabilities by May 8, 2026, and advised discontinuing use of the end-of-life D-Link DIR-823X if it could not be secured. The agency also urged organizations to apply vendor fixes, monitor for suspicious activity, and disconnect vulnerable SimpleHelp systems if mitigations were unavailable.
On April 24, 2026, CISA added CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9 Server, and CVE-2025-29635 in D-Link DIR-823X routers to its Known Exploited Vulnerabilities catalog. The agency cited evidence of active exploitation for all four vulnerabilities.
Alongside the Firestarter disclosure, Cisco and CISA released indicators of compromise, YARA-based detection guidance, and mitigation advice. Cisco strongly recommended reimaging affected devices and upgrading to fixed releases because the malware can survive reboots, updates, and patches.
On April 24, 2026, CISA and the U.K. NCSC publicly warned about the previously unknown Firestarter backdoor affecting Cisco ASA and FTD devices and said it had compromised at least one unnamed U.S. federal agency. The agencies assessed the activity could be part of a broader campaign targeting government and critical national infrastructure networks.
In an incident investigated by CISA and partners, a threat actor later tracked as UAT-4356 gained initial access to a U.S. Federal Civilian Executive Branch agency by exploiting CVE-2025-20333 and/or CVE-2025-20362 on a Cisco Firepower device running ASA software. The actor deployed the Line Viper shellcode loader and then installed the Firestarter backdoor.
In the federal civilian agency intrusion, attackers retained or regained access to the compromised Cisco ASA/FTD device through March 2026 even after patches were deployed. The case showed roughly six months of dwell time and demonstrated that Firestarter persistence could survive normal remediation short of hard power cycling or full reimaging.
Coverage of the Firestarter/ArcaneDoor campaign said Cisco Talos attributed the activity to UAT-4356 and that Microsoft tracks the same China-nexus actor as Storm-1849. This added a new attribution detail to the campaign affecting Cisco ASA and FTD devices.
CISA said attackers had installed the Firestarter backdoor on a Cisco security appliance protecting a U.S. federal civilian agency before the end of September 2025. The intrusion also involved the Line Viper shellcode loader, with Firestarter used to maintain persistent access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcesecpod.com
Open sourcethecyberthrone.in
Open sourcecybersecuritynews.com
Open sourcebankinfosecurity.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.