Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»WiFi / Internet & Networking»Infected Cisco firewalls need cold start to clear persistent Firestarter backdoor
    WiFi / Internet & Networking

    Infected Cisco firewalls need cold start to clear persistent Firestarter backdoor

    adminBy adminApril 28, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Cisco
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In a separate advisory, Cisco’s Talos threat intelligence service said a group it calls UAT-4356 is behind Firestarter, as part of its continued targeting of Firepower devices. Other researchers call the group Storm-1849, and identify the campaign targeting networking devices from Cisco and other vendors as ArcaneDoor, dating back to 2023.

    Critical failure in ‘patch and forget’ mentality

    CISA believes threat actors compromised Cisco firewalls by exploiting CVE-2025-20333 and/or CVE-2025-20362 early last September, before patches to plug these holes were released.

    In the example analyzed by the CISA, the hacker then deployed the LineViper shellcode loader to install a VPN that the threat actor could use to access all configuration elements of the compromised Firepower device, including administrative credentials and certificates and private keys. Then the Firestarter backdoor was added and used to link to a command and control server, which allowed the backdoor to persist even after patching. All this happened before patches to the two vulnerabilities were issued.

    Firestarter achieves persistence by detecting termination signals and relaunching itself, which is how it can survive firmware updates and device reboots unless a hard power cycle occurs.

    “The Firestarter malware represents a critical failure in the ‘patch and forget’ mentality of modern network security,” said IT analyst Rob Enderle of the Enderle Group.

    “What makes this attack particularly unusual is its technical resilience and anti-forensic capabilities,” he said. “The malware registers callback functions for termination signals like SIGTERM or SIGHUP, which allows it to automatically relaunch if an admin tries to kill the process. It deep-dives into the LINA engine’s virtual memory to hook the C++ standard library, intercepting WebVPN requests to trigger its payload. By using ‘time stomping’ to mask its file presence and redirecting errors to /dev/null, it remains nearly invisible to traditional discovery tools.”

    backdoor Cisco Clear cold FIRESTARTER firewalls Infected Persistent start
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleFresh Wave of GlassWorm VS Extensions Slices Through Supply Chain
    Next Article Cyber Insurance Data Gives CISOs New Ammo for Budget Talks
    admin
    • Website

    Related Posts

    AI data flows force rethink of data center networking at Backblaze

    April 28, 2026

    Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

    April 27, 2026

    US, UK authorities warn that Firestarter backdoor malware survives patching

    April 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Video service Vimeo confirms Anodot breach exposed user data

    April 28, 2026

    LinkedIn expands Event Ads beyond its own platform

    April 28, 2026

    Cyber Insurance Data Gives CISOs New Ammo for Budget Talks

    April 28, 2026

    Infected Cisco firewalls need cold start to clear persistent Firestarter backdoor

    April 28, 2026
    Categories
    • Blogging (69)
    • Cybersecurity (1,560)
    • Privacy & Online Earning (186)
    • SEO & Digital Marketing (957)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (249)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Video service Vimeo confirms Anodot breach exposed user data

    April 28, 2026

    LinkedIn expands Event Ads beyond its own platform

    April 28, 2026

    Cyber Insurance Data Gives CISOs New Ammo for Budget Talks

    April 28, 2026
    Most Popular
    • Video service Vimeo confirms Anodot breach exposed user data
    • LinkedIn expands Event Ads beyond its own platform
    • Cyber Insurance Data Gives CISOs New Ammo for Budget Talks
    • Infected Cisco firewalls need cold start to clear persistent Firestarter backdoor
    • Fresh Wave of GlassWorm VS Extensions Slices Through Supply Chain
    • The AI Skills Salary Premium
    • VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
    • How we Build with AI
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.