State-linked actor targets Cisco email and web appliances
Cisco Talos reports that an advanced persistent threat group it tracks as UAT-9686, likely Chinese-linked, is actively exploiting CVE-2025-20393 against Cisco AsyncOS-based appliances, specifically Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. In these intrusions the adversary deploys a custom Python backdoor called AquaShell together with supporting tools: AquaTunnel for a reverse SSH tunnel, the tunnelling tool Chisel, and AquaPurge for log cleanup. The campaign has run since at least late November 2025, and Talos emphasises that non-standard configurations amplify the risk.
What this means for your organisation
The email gateway sees all inbound and outbound mail in clear text. A backdoor there grants access to the correspondence itself, not merely to the network. The actor's log cleanup makes investigation difficult and may affect your ability to document the scope to a regulator. State-linked espionage is particularly relevant for suppliers to the public sector and critical infrastructure.
Berigo recommends
- Follow Cisco's security guidance for the affected products and review your configuration against the vendor's recommended setup.
- Ship email gateway logs to an external collector the attacker cannot clean.
- Look for unexpected outbound SSH connections from the email infrastructure.
- Assess whether your organisation is a plausible intelligence target, and let that set your detection level.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch