INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Firestarter Exploits Cisco Firewall Vulnerabilities

| 2026-04-24 20:34 MEDIUM HIGH
Executive Summary AI-generated
The threat actor behind the Firestarter backdoor, a custom malware designed to persist on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software, is believed to be a nation-state threat. The attack has been attributed to UAT-4356, known for cyberespionage campaigns including ArcaneDoor. This suggests that the attacker was using an internal identifier and may have had prior knowledge of the vulnerabilities exploited by Firestarter.
Technical Mitigations AI-generated
* Implement a "show kernel process | include lina_cs" command to detect and identify compromised Firepower devices, which can help determine if the device is still vulnerable to the Firestarter backdoor. * Run the 'show kernel process | include lina_cs' command on any resulting output from this command to confirm whether the device has been compromised by the Firestarter implant. * Reimage and upgrade Cisco Firepower or Secure Firewall devices using fixed releases that cover both compromised and non-compromised cases, as recommended by Cisco. * Use YARA rules (e.g. "Firestarter" or "Line Viper") to detect the Firestarter backdoor when applied to a disk image or core dump from a device, which can help identify potential compromises. * Implement a cold restart procedure for devices that have been compromised by the Firestarter implant, as this may be necessary to remove the malware and prevent further exploitation.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ArcaneDoorArcaneDoor CVE-2025-20362CVE-2025-20362 CVE-2025-20333CVE-2025-20333
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎early 2024
Threat actors used ArcaneDoor to target UAT-4356, a Cisco Talos-powered firewall update.
organisation Censys
target_region China
tactic Espionage
campaign ArcaneDoor
‎at least late 2025
Threat actors used a custom backdoor developed by Firestarter malware to target Cisco network security devices.
source_region United Kingdom
‎September 2025
Firestarter malware used Next to modify the CSP_MOUNT_LIST boot/mount file, stored a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log and restored it to /usr/bin/lina_cs.
organisation Firestarter
organisation Next
organisation ELF
organisation XML
organisation Firepower
organisation Once Firestarter
‎early September 2025
Threat actors used a known vulnerability in the Cisco firewall to target systems before the agency implemented security patches.
‎2026/04/24
UAT-4356 exploited vulnerabilities in Cisco Firepower devices' Adaptive Security Appliance and FTD software to gain initial entry.
organisation National Cyber Security Centre
organisation CVE-2025
organisation Snort
organisation the Cisco Service Platform
organisation LINA
organisation Cisco’s Adaptive Security Appliance and
organisation Firestarter
organisation RayInitiator
organisation Cisco’s ASA
organisation FTD
organisation XML
organisation the Secure Firewall 1200, 3100
organisation CyberScoop
organisation Cisco Technical Assistance
organisation Cisco Firepower Devices
organisation Cisco Firepower
organisation Cisco’s Security Advisory
organisation Cisco Service Platform
organisation CSP
organisation CSP_MOUNT_LIST
organisation 0x2
organisation API
organisation TAC
organisation ClamAV
financial 0 Generic-10059965
‎May 12
Threat actors used a firestarter malware to bypass Cisco firewall updates and security patches.
organisation the Autonomous Validation Summit
general_metric 14 May
Tactical Metrics
Metrics
financial
0
Generic-10059965
Intelligence Sources