{"id":8111,"date":"2025-11-01T10:04:18","date_gmt":"2025-11-01T10:04:18","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/01\/hackers-exploiting-cisco-ios-xe-vulnerability-in-the-wild-to-deploy-badcandy-web-shell\/"},"modified":"2025-11-01T10:04:18","modified_gmt":"2025-11-01T10:04:18","slug":"hackers-exploiting-cisco-ios-xe-vulnerability-in-the-wild-to-deploy-badcandy-web-shell","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/01\/hackers-exploiting-cisco-ios-xe-vulnerability-in-the-wild-to-deploy-badcandy-web-shell\/","title":{"rendered":"Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell"},"content":{"rendered":"<p>    Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals and state-sponsored actors are ramping up attacks on unpatched Cisco IOS XE devices across Australia, deploying a persistent Lua-based web shell known as BADCANDY to maintain unauthorized access.<\/p>\n<p>This implant, first spotted in variations since October 2023, has seen renewed exploitation throughout 2024 and into 2025, exploiting the critical CVE-2023-20198 vulnerability in the software\u2019s web user interface.<\/p>\n<p>The Australian Signals Directorate (ASD) warns that over 400 devices were potentially compromised since July 2025, with more than 150 still infected as of late October, highlighting the ongoing threat to network infrastructure.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"persistent-threat-from-cve-2023-20198\"><strong>BADCANDY Web Shell Exploiting Unpatched Devices<\/strong><\/h2>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/exploited-vulnerabilities-2023\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-20198<\/a> flaw, rated at a maximum CVSS score of 10.0, allows remote unauthenticated attackers to create highly privileged accounts on affected Cisco IOS XE routers and switches, granting full system control without credentials.<\/p>\n<p>Cisco patched this zero-day in October 2023 amid active exploitation, but public exploits emerged shortly after, fueling widespread abuse by groups like the Chinese state-sponsored <a href=\"https:\/\/cybersecuritynews.com\/chinese-salt-typhoon-hackers-exploiting-exchange-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">SALT TYPHOON<\/a>.<\/p>\n<p>ASD reports that attackers often apply a non-persistent patch post-compromise to hide the vulnerability, while installing BADCANDY\u2014a lightweight implant that enables root-level command execution via a hidden URI path in an Nginx configuration file named cisco_service.conf.<\/p>\n<p>Although BADCANDY vanishes upon reboot, attackers can retain access through stolen credentials or other persistence methods, making re-exploitation trivial on exposed web interfaces.\u200b<\/p>\n<p>This vulnerability ranked among the top routinely exploited flaws in 2023, and ASD confirms ongoing attacks in 2025, particularly targeting internet-facing devices.<\/p>\n<p>SALT TYPHOON, linked to Chinese intelligence, has leveraged similar Cisco weaknesses in global telecom breaches, often using legitimate credentials alongside exploits like CVE-2023-20198 and <a href=\"https:\/\/cybersecuritynews.com\/malicious-ips-cisco-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-20273<\/a>.<\/p>\n<p>Criminal actors and other nation-states are also reusing BADCANDY, scanning for unpatched systems and re-infecting those cleared by notifications.<\/p>\n<p>The implant\u2019s low footprint makes detection challenging without deep configuration reviews, underscoring risks to edge networks worldwide.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"asds-response-and-infection-trends\"><strong>ASD\u2019s Response<\/strong><\/h2>\n<p>In response, ASD has issued bulk notifications to affected entities via service providers, urging immediate patching, reboots, and incident response since July 2025.<\/p>\n<p>These efforts reduced infections from over 400 to around 150 by late October, but fluctuations suggest actors detect and re-exploit cleared devices.<\/p>\n<p>A graph tracking BADCANDY implants from July to October 2025 shows a steady decline punctuated by spikes around bulk notification events in September and early October, with the line dropping from 350 in mid-July to about 138 by late October. <\/p>\n<p>ASD attributes resurgences to unpatched systems left online, emphasizing that reboots alone won\u2019t suffice without addressing the root vulnerability.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg2wnu_ZRDhbt9gsPoBbcFcOcEw8nx-SQZ971KlgKoE1zqKG9dh4TF1opfZih3T5Ub9W-ebRrOE_Uw2LV0Tg75dh8SndYYA7_ousRSV9UTEDADXG_UHNB-DDyql1IW1Ocrzj1ARFfWzGz-3uVAZMc_xNXuhfDTNbqdzy6xrG29Wv888FkgU_kE0jjQjcNNc\/s16000\/Cisco%2520IOS%2520XE.webp?ssl=1\" alt=\"\"><\/figure>\n<p>To combat this, ASD recommends reviewing running configurations for privilege 15 accounts, especially suspicious ones like \u201ccisco_tac_admin\u201d or those with random strings, and removing unauthorized entries.<\/p>\n<p>Organizations should also scan for unknown tunnel interfaces, such as \u201cinterface tunnel[number]\u201d with unexpected IPs, and check TACACS+ logs for changes if enabled.<\/p>\n<p>Applying Cisco\u2019s patch for <a href=\"https:\/\/cybersecuritynews.com\/50k-cisco-ios-devices-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-20198<\/a> is critical, alongside disabling the HTTP server feature and following the IOS XE hardening guide to restrict web UI access.<\/p>\n<p>Rebooting removes the implant but requires post-reboot checks for lingering changes, and broader edge-device security, such as network segmentation, can prevent lateral movement.<\/p>\n<p>Cisco provides indicators of compromise in its advisory to aid investigations, while ASD continues notifications to shrink the attack surface in Australia. By prioritizing these actions, networks can thwart re-exploitation and bolster defenses against evolving threats.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-ios-xe-badcandy-web-shell\/\">Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-ios-xe-badcandy-web-shell\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell Cybercriminals and state-sponsored actors are ramping up attacks on unpatched Cisco IOS XE devices across Australia, deploying a persistent Lua-based web shell known as BADCANDY to maintain unauthorized access. This implant, first spotted in variations since October 2023, has seen renewed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-8111","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8111"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8111"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8111\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}