The Containment Era is here. →Explore

Executive Summary

In June 2024, Australian cybersecurity authorities issued urgent warnings regarding ongoing cyberattacks targeting unpatched Cisco IOS XE devices across the country. Threat actors exploited known vulnerabilities to install the BadCandy webshell, enabling persistent, covert access to network infrastructure. Once a device was compromised, attackers leveraged the foothold for lateral movement, unauthorized surveillance, and potentially for command-and-control activities, putting government entities, businesses, and ISPs at risk. The infections are widespread and ongoing due to delayed patching and lack of robust segmentation.

This incident highlights an increasing trend of sophisticated exploitation of edge network devices, demonstrating attackers’ focus on device-level vulnerabilities and lateral movement methods. The urgency is heightened by the scale and automation of attacks and the continued use of vulnerable systems.

Why This Matters Now

A surge in BadCandy infections demonstrates that critical infrastructure is at heightened risk when network devices remain unpatched. With attackers automating exploitation, organizations must accelerate patch cycles and strengthen segmentation controls to counter these evolving tactics and prevent widespread disruption.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Failure to promptly patch network devices and inadequate network segmentation exposed organizations to lateral movement and persistent compromise, falling short of NIST and PCI segmentation and monitoring requirements.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west traffic controls, inline IPS, egress policy enforcement, and deep anomaly detection would meaningfully constrain or rapidly detect adversary activities in each kill chain phase, preventing lateral spread, data exfiltration, and persistent C2. Applying these controls to network infrastructure and workloads reduces the attack surface and limits attacker freedom even in the event of initial compromise.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Prevents direct exploitation of unpatched routers by restricting external access.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Alerts on suspicious privilege escalation or shell activity.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Blocks unauthorized east-west communication between network segments.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detects and blocks known C2 patterns or suspicious outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized outbound transfers to attacker infrastructure.

Impact (Mitigations)

Rapid detection and correlation of impacts across the environment supports swift response.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Data Transmission
  • Remote Access Services
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive configuration data and network credentials, leading to unauthorized access and data exfiltration.

Recommended Actions

  • Enforce strict cloud firewall policies to minimize exposure of management interfaces on network devices.
  • Deploy east-west segmentation controls to restrict attacker movement post-compromise.
  • Enable inline IPS and network anomaly detection to surface exploitation and privilege misuse attempts.
  • Apply egress filtering policies that block unauthorized outbound connections and data transfer.
  • Centralize multicloud visibility for rapid incident detection, correlation, and response across all network assets.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image