US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

https://www.securityweek.com/us-federal-agencys-cisco-firewall-infected-with-firestarter-backdoor/

Publish Date: 2026-04-24 07:26:00

Source Domain: www.securityweek.com

At least one US federal agency was infected with a backdoor as part of a widespread China-linked espionage campaign targeting Cisco firewalls.

In May 2024, Cisco patched two vulnerabilities in its Adaptive Security Appliance (ASA) firewall platform that had been exploited as zero-days in a state-sponsored campaign tracked as ArcaneDoor.

A year later, the company fixed two more zero-days linked to the same campaign, tracked as CVE-2025-20333 and CVE-2025-20362, and impacting the VPN web server of ASA and Secure Firewall Threat Defense (FTD) software.

In September 2025, the US cybersecurity agency CISA issued Emergency Directive 25-03 (ED 25-03), urging federal agencies to patch vulnerable Cisco devices in their environments immediately. In November, CISA updated its guidance to recommend additional mitigation actions.

On Thursday, the agency updated ED 25-03 again, warning that patching vulnerable Cisco firewall devices did not remove malware deployed on them.

Per the updated directive, federal agencies should upload device core dumps to the Malware Next Gen portal to verify whether they have been compromised, and notify CISA immediately if they have been, or apply the available patches if needed.

Advertisement. Scroll to continue reading.

The requirement applies to Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series devices. All checks and updates should be performed by 11:59 PM EST on April 24, 2026, and devices should be hard-reset by April 30, CISA’s directive mandates.

CISA’s updated directive is accompanied by instructions on the core dumps and by a deep dive into the Firestarter backdoor, which was identified as the malware used in these attacks.

According to CISA, at least one federal agency was infected with Firestarter through the exploitation of a Firepower device vulnerable to CVE-2025-20333 and CVE-2025-20362. The backdoor is not removed by firmware updates, and devices…

Source