State-linked actor targets Cisco email and web appliances

Cisco Talos reports that an advanced persistent threat group it tracks as UAT-9686, likely Chinese-linked, is actively exploiting CVE-2025-20393 against Cisco AsyncOS-based appliances, specifically Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. In these intrusions the adversary deploys a custom Python backdoor called AquaShell together with supporting tools: AquaTunnel for a reverse SSH tunnel, the tunnelling tool Chisel, and AquaPurge for log cleanup. The campaign has run since at least late November 2025, and Talos emphasises that non-standard configurations amplify the risk.

What this means for your organisation

The email gateway sees all inbound and outbound mail in clear text. A backdoor there grants access to the correspondence itself, not merely to the network. The actor's log cleanup makes investigation difficult and may affect your ability to document the scope to a regulator. State-linked espionage is particularly relevant for suppliers to the public sector and critical infrastructure.

Berigo recommends

  • Follow Cisco's security guidance for the affected products and review your configuration against the vendor's recommended setup.
  • Ship email gateway logs to an external collector the attacker cannot clean.
  • Look for unexpected outbound SSH connections from the email infrastructure.
  • Assess whether your organisation is a plausible intelligence target, and let that set your detection level.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch