Isometric network nodes representing diverse global cyber threats and exploitation.

Daily Cybersecurity News - December 20, 2025

Cisco AsyncOS Zero-Day Exploitation

Executive Summary

A China-linked APT, UAT-9686, is actively exploiting a zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS software, targeting Cisco Secure Email Gateway and Web Manager. This allows attackers to execute arbitrary commands with root privileges.

Key TTPs

  • Initial Access: Exploitation of CVE-2025-20393, a zero-day vulnerability in Cisco AsyncOS software when the Spam Quarantine feature is enabled and reachable from the internet.
  • Execution: Execution of system-level commands with root privileges on the underlying operating system.
  • Defense Evasion: Embedding AquaShell into existing files and using encoded data blobs.

Campaign Analysis

The APT group UAT-9686, believed to be linked to China, is using the vulnerability to drop malware, including Chisel and the Aqua family, on vulnerable appliances. This campaign has been active since at least late November 2025, with evidence of persistence mechanisms being planted.

Targeting & Infrastructure

  • Target Profile: Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS software with the Spam Quarantine feature exposed to the internet.
  • Infrastructure: Utilizes tunneling tools like Chisel and AquaTunnel, along with the AquaShell backdoor.
PRO TIP: This exploit proves that even enterprise-grade gateways are single points of failure. If your organization's email filter gets hacked, everything inside is exposed. Don't rely solely on the "corporate umbrella" for safety. Segregate your personal digital life from your work identity to protect your inbox from infrastructure-level attacks.

Relevant Terms

  • Zero-Day: A vulnerability that is unknown to the vendor and for which no patch is available.
  • APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign, usually conducted by state-sponsored actors.
Source: Dark Reading

LongNosedGoblin APT: Cyberespionage Campaign

Executive Summary

LongNosedGoblin, a China-aligned APT, is targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group leverages Group Policy to deploy malware and move laterally across compromised networks.

Key TTPs

  • Initial Access: Abuses Active Directory Group Policy for malware deployment.
  • Execution: Employs custom C#/.NET tools, including NosyHistorian, NosyDoor, and NosyStealer.
  • Defense Evasion: Bypasses AMSI and uses "living-off-the-land" techniques.

Campaign Analysis

LongNosedGoblin utilizes a unique toolset and Group Policy abuse, distinguishing it from other China-aligned actors. The group focuses on long-term access and sustained intelligence collection within sensitive networks.

Targeting & Infrastructure

  • Target Profile: Governmental entities in Southeast Asia and Japan.
  • Infrastructure: Uses cloud services like Microsoft OneDrive and Google Drive for C2.

Actionable Intelligence

  • IPs:118.107.234[.]26
  • Hashes:4E3F6E9D0F443F4C42974A0551EEE957B498DA3D, 154A35DD4117DB760699C2092AFB307E94008506

Relevant Terms

  • APT: Advanced Persistent Threat - a sophisticated, long-term cyberattack targeting specific entities.
  • C2: Command and Control - infrastructure used by attackers to control compromised systems.
Source: Dark Reading

Deepfake Impersonation Campaign Targets U.S. Officials

Executive Summary

Malicious actors are using AI-powered voice cloning tools to impersonate U.S. government officials in an effort to extract sensitive information or conduct scams. The campaign, which dates back to 2023, targets individuals, including officials' family members and personal acquaintances.

Key TTPs

  • Initial Access: SMS texting to initiate contact.
  • Execution: AI-powered voice cloning tools and encrypted messaging apps (Signal, WhatsApp, Telegram) to impersonate officials.
  • Defense Evasion: Transitioning conversations to encrypted messaging apps.

Campaign Analysis

The use of AI-generated deepfakes is becoming increasingly sophisticated, making detection more challenging. This campaign highlights the potential for significant financial and reputational harm through social engineering.

Targeting & Infrastructure

  • Target Profile: Senior U.S. state government, White House, and Cabinet level officials, members of Congress, their family members, and personal acquaintances.
  • Infrastructure: Encrypted apps like Signal, WhatsApp, and Telegram.

Relevant Terms

  • Deepfake: AI-generated media that convincingly impersonates someone, often through altered video or audio.
  • Vishing: The act of using voice communication to trick individuals into divulging private information.
Source: CyberScoop

DOJ Charges 54 in ATM Jackpotting Conspiracy

Executive Summary

The U.S. Department of Justice indicted 54 individuals connected to the Tren de Aragua (TdA) for deploying Ploutus malware in a nationwide ATM jackpotting scheme. The scheme targeted ATMs across the U.S. to steal millions of dollars.

The Scheme

  • TTP 1: Conducted reconnaissance of ATMs at banks and credit unions.
  • TTP 2: Installed Ploutus malware via USB or by replacing the ATM's hard drive.
  • TTP 3: Forced ATMs to dispense cash, deleting evidence of the malware.

The Players

  • Threat Actor: [Tren de Aragua (TdA)].
  • Facilitators Arrested: [54 individuals, including Jimena Romina Araya Navarro].

The Consequence

  • Outcome: [Defendants face imprisonment ranging from 20 to 335 years if convicted].
  • Assets Seized/Forfeited: [$40.73 million].

Strategic Takeaway

The ATM jackpotting scheme highlights the evolving threat landscape and the use of cybercrime to fund terrorist activities.

Relevant Terms

  • ATM Jackpotting: Forcing an ATM to dispense all its cash by installing malware.
  • Malware: Software designed to cause damage to a computer or network.

Ukrainian National Pleads Guilty in Nefilim Ransomware Scheme

Executive Summary

The DOJ announced that Artem Stryzhak pleaded guilty to conspiracy to commit computer fraud for his role in deploying the Nefilim ransomware against victim computer networks in the United States and other countries. Authorities are offering an $11 million reward for information on his alleged co-conspirator, Volodymyr Tymoshchuk.

The Scheme

  • TTP 1: Customized ransomware executable files for each victim.
  • TTP 2: Created unique decryption keys and ransom notes.
  • TTP 3: Threatened to publish stolen data on "Corporate Leaks" websites.

The Players

  • Threat Actor: Nefilim Ransomware Group
  • Facilitators Arrested:Artem Aleksandrovych Stryzhak

The Consequence

  • Outcome: Stryzhak pleaded guilty to conspiracy to commit computer fraud and faces up to 10 years in prison.

Strategic Takeaway

This guilty plea highlights the continued efforts to pursue and prosecute cybercriminals involved in ransomware attacks, regardless of their location.

Relevant Terms

  • Ransomware: A type of malware that encrypts a victim's files, demanding a ransom payment for the decryption key.
  • Extradition: The legal process by which a country transfers a person to another country for prosecution or punishment.
Source: CyberScoop