Executive Summary
In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection.
This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.
Why This Matters Now
This campaign represents a critical inflection point as nation-state actors increasingly exploit zero-days in network infrastructure to gain covert, persistent access to sensitive environments. The rapid issuance of federal directives highlights urgent operational and regulatory risks to organizations still relying on unpatched or unsupported perimeter devices.
Attack Path Analysis
The attackers initiated the campaign by exploiting zero-day vulnerabilities in Cisco ASA firewalls to gain unauthorized access to agency networks. After initial compromise, they escalated privileges to obtain persistent administrative control, implanting malware and modifying device behavior. Leveraging compromised firewall devices, the attackers enabled lateral movement across protected segments within victim networks. They established command and control by disabling logging, intercepting CLI commands, and using covert channels to maintain remote access and issue commands. Exfiltration occurred as data was siphoned from internal resources through the compromised perimeter devices, possibly using encrypted or obfuscated outbound flows. The overall impact included persistent unauthorized access, stealthy data theft, and risk to mission-critical assets across federal networks.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) in Cisco ASA firewall appliances to gain remote, unauthenticated access to agency networks.
Related CVEs
CVE-2025-20333
CVSS 9.8A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an authenticated, remote attacker to execute arbitrary code on an affected device.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – 9.16 and earlier
Cisco Secure Firewall Threat Defense (FTD) Software – 7.0 and earlier
Exploit Status:
exploited in the wildCVE-2025-20362
CVSS 7.5A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to access restricted URL endpoints related to remote access VPN.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – 9.16 and earlier
Cisco Secure Firewall Threat Defense (FTD) Software – 7.0 and earlier
Exploit Status:
exploited in the wildCVE-2025-20363
CVSS 9.8A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software allows an unauthenticated, remote attacker to execute arbitrary code on an affected device.
Affected Products:
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software – 9.16 and earlier
Cisco Secure Firewall Threat Defense (FTD) Software – 7.0 and earlier
Cisco IOS Software – 15.2 and earlier
Cisco IOS XE Software – 16.9 and earlier
Cisco IOS XR Software – 6.5 and earlier
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Hardware Additions
Valid Accounts
Indicator Removal on Host: File Deletion
Impair Defenses: Disable Windows Event Logging
Command and Scripting Interpreter
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Log Management and Review
Control ID: 10.2.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Comprehensive Monitoring and Threat Detection
Control ID: Capabilities: Visibility and Analytics
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21
PCI DSS 4.0 – Security Vulnerability Management
Control ID: 6.3.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face immediate critical risk from Cisco ASA zero-day exploits enabling nation-state persistence, requiring emergency patching by Friday deadline.
Defense/Space
Defense infrastructure highly vulnerable to Chinese espionage group exploiting Cisco firewall zero-days for remote code execution and data exfiltration capabilities.
Financial Services
Banking networks at severe risk from sophisticated nation-state attacks targeting Cisco ASAs, threatening data integrity and regulatory compliance frameworks.
Health Care / Life Sciences
Healthcare organizations face critical exposure through Cisco firewall vulnerabilities enabling persistent access, compromising patient data and HIPAA compliance requirements.
Sources
- CISA alerts federal agencies of widespread attacks using Cisco zero-dayshttps://cyberscoop.com/cisa-emergency-directive-cisco-zero-days/Verified
- CISA Issues Emergency Directive Requiring Federal Agencies to Identify and Mitigate Cisco Zero-Day Vulnerabilitieshttps://www.cisa.gov/news-events/news/cisa-issues-emergency-directive-requiring-federal-agencies-identify-and-mitigate-cisco-zero-dayVerified
- CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Deviceshttps://www.cisa.gov/news-events/alerts/2025/09/25/cisa-directs-federal-agencies-identify-and-mitigate-potential-compromise-cisco-devicesVerified
- Cisco Event Response: Continued Attacks Against Cisco Firewallshttps://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Cloud Network Security Framework controls such as zero trust segmentation, east-west traffic inspection, inline intrusion prevention, egress policy enforcement, and multicloud visibility would have greatly restricted the attacker's ability to move laterally, hide C2 traffic, and exfiltrate sensitive data—limiting both the reach and persistence of this campaign.
Control: Cloud Firewall (ACF) + Inline IPS (Suricata)
Mitigation: Prevention or detection of exploit attempts targeting firewall interfaces.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Detection of privilege escalation and suspicious device modifications.
Control: Zero Trust Segmentation + East-West Traffic Security
Mitigation: Blocked or tightly limited unauthorized lateral movement between network zones.
Control: Threat Detection & Anomaly Response + Multicloud Visibility & Control
Mitigation: Anomalous communications and evasion attempts quickly detected and alerted.
Control: Egress Security & Policy Enforcement + Encrypted Traffic (HPE)
Mitigation: Outbound data transfer policy violations blocked or alerted.
Reduced operational impact and faster threat containment.
Impact at a Glance
Affected Business Functions
- Network Security
- Remote Access Services
- Data Protection
Estimated downtime: 5 days
Estimated loss: $500,000
Potential unauthorized access to sensitive data due to compromised firewall devices.
Recommended Actions
Key Takeaways & Next Steps
- • Urgently patch or disconnect vulnerable Cisco ASA firewall devices and deploy inline IPS/firewalls to block future exploit attempts.
- • Implement zero trust segmentation and microsegmentation to contain lateral movement from any single compromised device or service.
- • Enforce comprehensive egress policies and inspect encrypted outbound traffic to detect and prevent data exfiltration.
- • Deploy advanced threat anomaly detection and continuous monitoring to quickly identify C2 communications and unauthorized system changes.
- • Centralize multicloud traffic visibility and automate incident response workflows for rapid isolation and recovery of affected cloud and hybrid assets.



