BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Australia Warns of BADCANDY Malware Targeting Cisco Devices

Australian Signals Directorate Warns of Ongoing BADCANDY Cyberattacks Exploiting Critical Cisco IOS XE Vulnerability

  • The Australian Signals Directorate (ASD) reports ongoing attacks on unpatched Cisco IOS XE devices using the BADCANDY implant.
  • BADCANDY exploits a critical vulnerability (CVE-2023-20198) that allows remote attackers to create privileged accounts and control devices.
  • An estimated 400 Cisco devices in Australia have been compromised since July 2025, with 150 infections reported in October alone.
  • BADCANDY is a non-persistent Lua-based web shell that can be reintroduced if devices remain unpatched and internet-exposed.
  • ASD urges applying patches, limiting exposure, removing unauthorized accounts, and following Cisco hardening guidelines to prevent further breaches.

The Australian Signals Directorate (ASD) has issued a bulletin warning about sustained cyberattacks targeting unpatched Cisco IOS XE devices across Australia. The attacks exploit a critical, previously undisclosed implant called BADCANDY. This implant leverages the vulnerability identified as CVE-2023-20198, which enables a remote, unauthenticated attacker to create accounts with elevated privileges and seize control of affected systems.

- Advertisement -

The vulnerability carries a maximum severity score of 10.0 and has been actively exploited in the wild since 2023. Threat actors linked to China, including a group known as Salt Typhoon, have used this exploit against telecommunications providers. Since October 2023, multiple variants of the BADCANDY implant have been detected, with the attacks ongoing into 2024 and 2025. ASD estimates that up to 400 devices were compromised in Australia from July 2025, with 150 infections recorded in October alone.

According to ASD, “BADCANDY is a low equity Lua-based web shell, and cyber actors have typically applied a non-persistent patch post-compromise to mask the device’s vulnerability status in relation to CVE-2023-20198.” This means the implant does not survive a system reboot, but attackers can reinstall it if the device remains vulnerable and connected to the internet. The agency observed attackers detecting and reinfecting devices after implant removal, even when previous notifications had been issued.

ASD emphasizes that rebooting infected devices only removes the implant temporarily and does not reverse other attacker actions. To prevent further exploitation, the agency advises system administrators to promptly apply patches, restrict public access to web interfaces, and follow the hardening guidelines issued by Cisco. Additional recommended actions include reviewing and removing unauthorized accounts with administrative privileges, inspecting unknown tunnel interfaces, and monitoring command logging if enabled.

These measures are critical to address the ongoing threats posed by this sophisticated implant and the exploitation of critical flaws in widely used network devices.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard Hack Ongoing: $88M Stolen in Three Waves

Galaxy Research now tracks roughly $88.6 million stolen from approximately 4,585 Coldcard addresses across...

STRC shares stay below $100 par, August dividend holds at 12%

Strategy's STRC preferred shares closed July at $89.46, well below their $100 par value,...

Can Apple Stock Double by 2030?

Apple trades near $295 as debate intensifies over whether the stock can double by...

Meta’s AI ‘pervert glasses’ spark privacy lawsuits and bans

Meta's AI-powered Ray-Ban smart glasses are facing a severe privacy backlash in 2026, with...

BNB Chain sues ex-employee over unauthorized memecoin

BNB Chain is pursuing legal action after a former employee allegedly used unauthorized access...

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading