The Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) have confirmed that threat actors are using FIRESTARTER malware to maintain persistence on Cisco network devices, allowing the threat actors to maintain access even after patching and reboots. 

FIRESTARTER malware targets Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software, which were previously compromised prior to September 2025. 

FIRESTARTER malware enables a persistent backdoor by hooking into the device’s core engine, allowing it to survive firmware updates, software upgrades, and regular reboots. It maintains persistence by detecting shutdown signals and automatically re-installing itself, so typical remediation methods fail. 

The threat actor is believed to be a state-sponsored threat actor known as UAT-4356. The attackers exploited CVE-2025-20333 (RCE) and CVE-2025-20362 (Auth Bypass) to install the malware. Because Firestarter survives standard patches, CISA warns that patching alone is insufficient if the device was compromised before a patch was installed. It recommends several measures, including physically unplugging the device from all power sources (including redundant power) for at least one minute. In addition, CISA and Cisco recommend completely wiping and reimaging affected Cisco devices to ensure the malware is completely removed.

Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.