
Daily Cybersecurity News – December 20, 2025
Cisco AsyncOS Zero-Day Exploitation
Executive Summary
A China-linked APT, UAT-9686, is actively exploiting a zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS software, targeting Cisco Secure Email Gateway and Web Manager. This allows attackers to execute arbitrary commands with root privileges.
Key TTPs
- Initial Access: Exploitation of CVE-2025-20393, a zero-day vulnerability in Cisco AsyncOS software when the Spam Quarantine feature is enabled and reachable from the internet.
- Execution: Execution of system-level commands with root privileges on the underlying operating system.
- Defense Evasion: Embedding AquaShell into existing files and using encoded data blobs.
Campaign Analysis
The APT group UAT-9686, believed to be linked to China, is using the vulnerability to drop malware, including Chisel and the Aqua family, on vulnerable appliances. This campaign has been active since at least late November 2025, with evidence of persistence mechanisms being planted.
Targeting & Infrastructure
- Target Profile: Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS software with the Spam Quarantine feature exposed to the internet.
- Infrastructure: Utilizes tunneling tools like Chisel and AquaTunnel, along with the AquaShell backdoor.
Relevant Terms
- Zero-Day: A vulnerability that is unknown to the vendor and for which no patch is available.
- APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign, usually conducted by state-sponsored actors.
Source: Dark Reading
LongNosedGoblin APT: Cyberespionage Campaign
Executive Summary
LongNosedGoblin, a China-aligned APT, is targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group leverages Group Policy to deploy malware and move laterally across compromised networks.
Key TTPs
- Initial Access: Abuses Active Directory Group Policy for malware deployment.
- Execution: Employs custom C#/.NET tools, including NosyHistorian, NosyDoor, and NosyStealer.
- Defense Evasion: Bypasses AMSI and uses "living-off-the-land" techniques.
Campaign Analysis
LongNosedGoblin utilizes a unique toolset and Group Policy abuse, distinguishing it from other China-aligned actors. The group focuses on long-term access and sustained intelligence collection within sensitive networks.
Targeting & Infrastructure
- Target Profile: Governmental entities in Southeast Asia and Japan.
- Infrastructure: Uses cloud services like Microsoft OneDrive and Google Drive for C2.
Actionable Intelligence
- IPs:
118.107.234[.]26 - Hashes:
4E3F6E9D0F443F4C42974A0551EEE957B498DA3D,154A35DD4117DB760699C2092AFB307E94008506
Relevant Terms
- APT: Advanced Persistent Threat - a sophisticated, long-term cyberattack targeting specific entities.
- C2: Command and Control - infrastructure used by attackers to control compromised systems.
Source: Dark Reading
Deepfake Impersonation Campaign Targets U.S. Officials
Executive Summary
Malicious actors are using AI-powered voice cloning tools to impersonate U.S. government officials in an effort to extract sensitive information or conduct scams. The campaign, which dates back to 2023, targets individuals, including officials' family members and personal acquaintances.
Key TTPs
- Initial Access: SMS texting to initiate contact.
- Execution: AI-powered voice cloning tools and encrypted messaging apps (Signal, WhatsApp, Telegram) to impersonate officials.
- Defense Evasion: Transitioning conversations to encrypted messaging apps.
Campaign Analysis
The use of AI-generated deepfakes is becoming increasingly sophisticated, making detection more challenging. This campaign highlights the potential for significant financial and reputational harm through social engineering.
Targeting & Infrastructure
- Target Profile: Senior U.S. state government, White House, and Cabinet level officials, members of Congress, their family members, and personal acquaintances.
- Infrastructure: Encrypted apps like Signal, WhatsApp, and Telegram.
Relevant Terms
- Deepfake: AI-generated media that convincingly impersonates someone, often through altered video or audio.
- Vishing: The act of using voice communication to trick individuals into divulging private information.
Source: CyberScoop
DOJ Charges 54 in ATM Jackpotting Conspiracy
Executive Summary
The U.S. Department of Justice indicted 54 individuals connected to the Tren de Aragua (TdA) for deploying Ploutus malware in a nationwide ATM jackpotting scheme. The scheme targeted ATMs across the U.S. to steal millions of dollars.
The Scheme
- TTP 1: Conducted reconnaissance of ATMs at banks and credit unions.
- TTP 2: Installed Ploutus malware via USB or by replacing the ATM's hard drive.
- TTP 3: Forced ATMs to dispense cash, deleting evidence of the malware.
The Players
- Threat Actor: [Tren de Aragua (TdA)].
- Facilitators Arrested: [54 individuals, including Jimena Romina Araya Navarro].
The Consequence
- Outcome: [Defendants face imprisonment ranging from 20 to 335 years if convicted].
- Assets Seized/Forfeited: [$40.73 million].
Strategic Takeaway
The ATM jackpotting scheme highlights the evolving threat landscape and the use of cybercrime to fund terrorist activities.
Relevant Terms
- ATM Jackpotting: Forcing an ATM to dispense all its cash by installing malware.
- Malware: Software designed to cause damage to a computer or network.
Source: The Hacker News
Ukrainian National Pleads Guilty in Nefilim Ransomware Scheme
Executive Summary
The DOJ announced that Artem Stryzhak pleaded guilty to conspiracy to commit computer fraud for his role in deploying the Nefilim ransomware against victim computer networks in the United States and other countries. Authorities are offering an $11 million reward for information on his alleged co-conspirator, Volodymyr Tymoshchuk.
The Scheme
- TTP 1: Customized ransomware executable files for each victim.
- TTP 2: Created unique decryption keys and ransom notes.
- TTP 3: Threatened to publish stolen data on "Corporate Leaks" websites.
The Players
- Threat Actor: Nefilim Ransomware Group
- Facilitators Arrested:Artem Aleksandrovych Stryzhak
The Consequence
- Outcome: Stryzhak pleaded guilty to conspiracy to commit computer fraud and faces up to 10 years in prison.
Strategic Takeaway
This guilty plea highlights the continued efforts to pursue and prosecute cybercriminals involved in ransomware attacks, regardless of their location.
Relevant Terms
- Ransomware: A type of malware that encrypts a victim's files, demanding a ransom payment for the decryption key.
- Extradition: The legal process by which a country transfers a person to another country for prosecution or punishment.
Source: CyberScoop