Full Breakdown
Ongoing Cyber Attacks Targeting Cisco IOS XE Devices in Australia
11/4/2025, 7:00:11 AM
Overview of the Cyber Threat
The Australian Signals Directorate (ASD) has issued a warning regarding ongoing cyber attacks exploiting a critical vulnerability in unpatched Cisco IOS XE devices. The attacks utilize a previously undocumented implant known as BADCANDY, which leverages the CVE-2023-20198 vulnerability, rated at a maximum CVSS score of 10.0. This flaw allows remote, unauthenticated attackers to create accounts with elevated privileges, enabling them to take control of affected systems. Since July 2025, over 400 devices in Australia have been compromised, with 150 infections reported in October 2025 alone.
Nature of the BADCANDY Implant
BADCANDY is characterized as a low-equity, Lua-based web shell that is non-persistent after a device reboot. However, attackers can regain access by reintroducing the malware if the device remains unpatched and exposed to the internet. ASD has observed that threat actors can detect when the BADCANDY implant is removed, leading to repeated infections of previously compromised devices. This ongoing cycle of re-exploitation underscores the critical need for system operators to apply security patches and limit public exposure of the web user interface.
Recommendations for Mitigation
To combat the BADCANDY threat, ASD recommends that organizations take several proactive measures. These include:
- Applying the necessary patches to address CVE-2023-20198.
- Limiting access to the web user interface of Cisco IOS XE devices.
- Reviewing device configurations for unauthorized accounts, particularly those with privilege 15 access.
- Monitoring for unknown tunnel interfaces and suspicious configuration changes.
Cisco has published security advisories detailing fixed software releases for affected IOS XE versions, emphasizing the importance of adhering to these guidelines to prevent future exploitation.
Criticism & Opposition
Despite the ASD's warnings and recommendations, the ongoing nature of these attacks raises concerns about the effectiveness of current cybersecurity measures in place. Critics argue that the persistence of the BADCANDY threat indicates a failure to adequately secure critical infrastructure, highlighting the need for more robust and immediate responses from organizations and cybersecurity agencies.
Official Statements & Responses
The ASD has stated, “BADCANDY is a low equity Lua-based web shell... the presence of the BADCANDY implant indicates compromise of the Cisco IOS XE device.” They emphasize the importance of patching and hardening guidelines to prevent future exploitation attempts. Additionally, they continue to notify affected entities and provide guidance on incident response and remediation.
Conflicting Reports & Gaps
While ASD reports over 400 compromised devices, the exact number of devices currently infected remains unclear, with estimates stabilizing around 150 as of late October 2025. This discrepancy suggests that while some remediation efforts have been successful, the threat actors are continuously scanning for and exploiting vulnerable systems.
Conclusion
The ongoing exploitation of Cisco IOS XE devices through the BADCANDY implant highlights significant vulnerabilities within critical infrastructure. Organizations must prioritize patching and security hardening to mitigate these risks effectively. The ASD continues to monitor the situation and provide guidance to ensure the security of affected systems.
