New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices

New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices

By Deeba Ahmed
Publication Date: 2026-04-28 11:41:00

The US Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) released a joint malware analysis report on 23 April 2026 regarding a dangerous new threat- a Linux-based ELF file called FIRESTARTER.

This malware is, reportedly, the current favourite of Advanced Persistent Threat (APT) actors as it allows them to maintain persistence on Cisco Firepower and Secure Firewall devices running firmware like Adaptive Security Appliance/ASA (software that handles basic firewall and VPN tasks) or Firepower Threat Defense/FTD (an advanced firewall system that combines multiple security features).

Attack Details

The agencies detected this campaign in early September 2025. As per their research, initial access was gained by exploiting two known vulnerabilities in Cisco ASA and FTD- CVE-2025-20333 (A buffer overflow vulnerability that lets hackers crash the system or run malicious code), and CVE-2025-20362 (A missing authorization…