{"id":9304,"date":"2025-12-18T10:03:43","date_gmt":"2025-12-18T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/18\/cisco-asyncos-0-day-vulnerability-exploited-in-the-wild-to-run-system-level-commands\/"},"modified":"2025-12-18T10:03:43","modified_gmt":"2025-12-18T10:03:43","slug":"cisco-asyncos-0-day-vulnerability-exploited-in-the-wild-to-run-system-level-commands","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/18\/cisco-asyncos-0-day-vulnerability-exploited-in-the-wild-to-run-system-level-commands\/","title":{"rendered":"Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands"},"content":{"rendered":"<p>    Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting <a href=\"https:\/\/cybersecuritynews.com\/hackers-bypass-secure-email-gateway\/\" target=\"_blank\" rel=\"noreferrer noopener\">Secure Email Gateway<\/a> (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). <\/p>\n<p>The attack, spotted since late November 2025 and publicly disclosed on December 10, allows attackers to run system-level commands and plant a persistent Python backdoor dubbed \u201cAquaShell.\u201d<\/p>\n<p>Talos attributes the operation with moderate confidence to UAT-9686, a <a href=\"https:\/\/cybersecuritynews.com\/chinese-student-charged-for-running-a-mass-smishing-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chinese-nexus<\/a> advanced persistent threat (APT) actor. Overlaps in tactics, techniques, procedures (TTPs), tooling, and infrastructure link UAT-9686 to groups like APT41 and UNC5174.<\/p>\n<p>Notably, the custom web implant AquaShell mirrors techniques adopted by sophisticated Chinese APTs for stealthy persistence.<\/p>\n<p>The intrusion vector hits appliances with non-standard configurations, as detailed in <a href=\"https:\/\/blog.talosintelligence.com\/uat-9686\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cisco\u2019s advisory<\/a>. Attackers embed AquaShell into \u201c\/data\/web\/euq_webui\/htdocs\/index.py\u201d via an encoded blob. This lightweight backdoor passively monitors for unauthenticated HTTP POST requests, decodes payloads with a custom algorithm plus Base64, and executes shell commands.<\/p>\n<p>Compromise escalates with supplementary tools: AquaTunnel, a GoLang ELF binary forked from open-source ReverseSSH, establishes reverse SSH tunnels for remote access past firewalls; Chisel, an open-source tunneler, proxies TCP\/UDP traffic over HTTP for internal pivoting; and AquaPurge, which scrubs logs by filtering out keyword-laden lines via egrep.<\/p>\n<p>The Secure Email and Web Manager centralizes oversight of the ESA and Web Security Appliance (WSA), including quarantine, policies, and reporting, making it a prime target for email gateway disruptions.<\/p>\n<p>Cisco urges customers to review the <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sma-attack-N9bf4\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advisory<\/a> for indicators of compromise (IOCs) and remediation.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Tool\/Component<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Value<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description \u200b<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">AquaTunnel<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA256 Hash<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">2db8ad6e0f43e93cc557fbda0271a436f9f2a478b1607073d4ee3d20a87ae7ef<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">GoLang ELF reverse SSH tunnel for remote access.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">AquaPurge<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA256 Hash<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">145424de9f7d5dd73b599328ada03aa6d6cdcee8d5fe0f7cb832297183dbe4ca<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Log-clearing utility using egrep to remove keywords.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Chisel<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA256 Hash<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">85a0b22bd17f7f87566bd335349ef89e24a5a19f899825b4d178ce6240f58bfc<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Open-source tunneling tool for TCP\/UDP proxying over HTTP.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Attacker IP<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">IP Address<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">172.233.67[.]176<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Command-and-control infrastructure.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Attacker IP<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">IP Address<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">172.237.29[.]147<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Command-and-control infrastructure.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Attacker IP<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">IP Address<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">38.54.56[.]95<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Command-and-control infrastructure.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This campaign underscores rising APT focus on email security edges amid supply chain risks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>AI-Powered ISO 27001, SOC 2, NIST, NIS 2, and GDPR Compliance Checklist =&gt; <a href=\"https:\/\/www.aiauditbuddy.com\/?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=cybersecuritynews_feature\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start for Free<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-asyncos-0-day-vulnerability\/\">Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-asyncos-0-day-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting Secure Email Gateway (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). The attack, spotted since late November 2025 and publicly disclosed on [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63,131,648],"tags":[130],"class_list":["post-9304","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9304"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9304"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9304\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}