Hackers turn Cisco and Citrix zero-days into a malware nightmare

  • CVE-2025-20337 enables unauthenticated remote code execution in Cisco ISE systems
  • Attackers deployed custom in-memory web shells with advanced evasion and encryption techniques
  • Exploits were widespread and indiscriminate, with no specific industry or actor attribution

“Sophisticated” threat actors have been using a maximum-severity zero-day vulnerability in Cisco Identity Service Engine (ISE) and Citrix systems to deploy custom backdoor malware, experts have claimed.

Amazon’s threat intelligence team said it recently stumbled upon an insufficient validation of user-supplied input vulnerability in Cisco ISE deployments, achieving pre-authentication remote code execution on compromised endpoints and providing administrator-level access to the systems.

The researchers discovered the intrusion while investigating a Citrix Bleed Two vulnerability which was also being exploited as a zero-day. The newly found bug is now tracked as CVE-2025-20337 and has been assigned a severity score of 10/10 (critical).

Hiding malware in custom fonts

“A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root,” the NVD page explains.

“The attacker does not require any valid credentials to exploit this vulnerability,” the advisory added, stressing that an attacker could exploit it by submitting a crafted API request.

The vulnerability was used to deploy a custom web shell disguised as a legitimate Cisco ISE component named IdentityAuditAction, Amazon further explained, noting the malware wasn’t typical, or off-the-shelf, but rather custom-built and designed specifically for Cisco ISE environments.

The web shell came with advanced evasion capabilities, including operating entirely in-memory, using Java reflection to inject itself into running threads, and registering as a listener to monitor all HTTP requests across the Tomcat server. It also implemented DES encryption with non-standard Base64 encoding, and required knowledge of specific HTTP headers to access.

Amazon did not attribute the attacks to any particular threat actor, and said that the attacks were not targeted at any specific industry or organization. Instead, it was used indiscriminately and against as many organizations as possible.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Samsung launches ‘Galaxy Card’ credit card

Samsung has announced its new credit card, the “Galaxy Card,” which offers up to 5% cashback on Galaxy device purchases. Read more @ 9to5google

SpaceX in your index fund, explained

AUUUUUGH | Image: Cath Virginia / The Verge, Getty Images Index funds are touted as one of the safest ways to invest. Rather than picking...

The Odyssey turned me into an IMAX believer

After seeing Christopher Nolan's The Odyssey for the first time early last week, I came away impressed, but somewhat conflicted about two of the...

The FCC is planning to retroactively ban disguised DJI gadgets

The Skyrover X1 vs the DJI Mini 4 Pro. | Image: AirPhotography Last October, we told you how the FCC had given itself the power...

Here are the 30,000 songs Sony is suing Udio’s AI music generator over

Sony Music Entertainment has filed another lawsuit against Udio, accusing the AI music generator of infringing the copyright of more than 30,000 of its...

Samsung is betting big that you’ll want the wide Galaxy Z Fold 8, report details

A new report reveals Samsung’s plans for the Galaxy Z Fold 8 series and the Galaxy Z Flip 8, with the company betting big...

Snapseed Camera adds geotags & saving originals on Android

Another update for the Snapseed Camera on Android this month introduces location metadata and support for saving the original image. Read more @ 9to5google

The Sideload 039: Digital landscaping

Welcome to episode 39 of The Sideload, a 9to5Google podcast. This week, Will is joined by Chris Wedel of Gadgets & Gravel to discuss the modern...

Google Photos toggle lets you switch between classic search & Ask Photos

Google Photos has rolled out a “classic search” toggle for Ask Photos that delivers a big quality-of-life improvement. Read more @ 9to5google

Adobe’s ‘natural look’ camera app embraces generative AI

Welcome to the “what is a photo” debate, Adobe. | Image: Adobe Adobe's experimental camera app has taken an unexpected turn. After Project Indigo was...