Cisco AsyncOS Zero-Day Exploitation
Executive Summary
A China-linked APT, UAT-9686, is actively exploiting a zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS software, targeting Cisco Secure Email Gateway and Web Manager. This allows attackers to execute arbitrary commands with root privileges.
Key TTPs
- Initial Access: Exploitation of CVE-2025-20393, a zero-day vulnerability in Cisco AsyncOS software when the Spam Quarantine feature is enabled and reachable from the internet.
- Execution: Execution of system-level commands with root privileges on the underlying operating system.
- Defense Evasion: Embedding AquaShell into existing files and using encoded data blobs.
Campaign Analysis
The APT group UAT-9686, believed to be linked to China, is using the vulnerability to drop malware, including Chisel and the Aqua family, on vulnerable appliances. This campaign has been active since at least late November 2025, with evidence of persistence mechanisms being planted.
Targeting & Infrastructure
- Target Profile: Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS software with the Spam Quarantine feature exposed to the internet.
- Infrastructure: Utilizes tunneling tools like Chisel and AquaTunnel, along with the AquaShell backdoor.
Relevant Terms
- Zero-Day: A vulnerability that is unknown to the vendor and for which no patch is available.
- APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign, usually conducted by state-sponsored actors.
Source: Dark Reading
