Sunday, November 2, 2025

ASD Warns of Ongoing BADCANDY Assaults Exploiting Cisco IOS XE Vulnerability


Nov 01, 2025Ravie LakshmananSynthetic Intelligence / Vulnerability

The Australian Alerts Directorate (ASD) has issued a bulletin about ongoing cyber assaults focusing on unpatched Cisco IOS XE gadgets within the nation with a beforehand undocumented implant often known as BADCANDY.

The exercise, per the intelligence company, includes the exploitation of CVE-2023-20198 (CVSS rating: 10.0), a vital vulnerability that enables a distant, unauthenticated attacker to create an account with elevated privileges and use it to grab management of vulnerable programs.

The safety defect has come below lively exploitation within the wild since final 2023, with China-linked menace actors like Salt Storm weaponizing it in current months to breach telecommunications suppliers.

DFIR Retainer Services

ASD famous that variations of BADCANDY have been detected since October 2023, with a recent set of assaults persevering with to be recorded in 2024 and 2025. As many as 400 gadgets in Australia are estimated to have been compromised with the malware since July 2025, out of which 150 gadgets had been contaminated in October alone.

“BADCANDY is a low fairness Lua-based internet shell, and cyber actors have usually utilized a non-persistent patch post-compromise to masks the gadget’s vulnerability standing in relation to CVE-2023-20198,” it mentioned. “In these cases, the presence of the BADCANDY implant signifies compromise of the Cisco IOS XE gadget, through CVE-2023-20198.”

The dearth of a persistence mechanism means it can not survive throughout system reboots. Nevertheless, if the gadget stays unpatched and uncovered to the web, it is doable for the menace actor to re-introduce the malware and regain entry to it.

ASD has assessed that the menace actors are capable of detect when the implant is eliminated and are infecting the gadgets once more. That is primarily based on the truth that re-exploitation has occurred on gadgets for which the company has beforehand issued notifications to affected entities.

That having mentioned, a reboot won’t undo different actions undertaken by the attackers. It is due to this fact important that system operators apply the patches, restrict public publicity of the online consumer interface, and observe vital hardening tips issued by Cisco to forestall future exploitation makes an attempt.

CIS Build Kits

Among the different actions outlined by the company are listed under –

  • Evaluate the working configuration for accounts with privilege 15 and take away surprising or unapproved accounts
  • Evaluate accounts with random strings or “cisco_tac_admin,” “cisco_support,” “cisco_sys_manager,” or “cisco” and take away them if not legit
  • Evaluate the working configuration for unknown tunnel interfaces
  • Evaluate TACACS+ AAA command accounting logging for configuration modifications, if enabled

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

PHP Code Snippets Powered By : XYZScripts.com