Description

Attackers based in China are taking advantage of vulnerabilities in Cisco ASA, which is widely used by governments and big organizations around the world. According to Palo Alto Networks' Unit 42, a China-linked group, known as Storm-1849, aka UAT4356, has been actively targeting Cisco ASA devices during October 2025. These appliances, popular for combining multiple security functions like firewalls, intrusion prevention, and antivirus protection, have become a high-value target for state-sponsored attackers. Unit 42 saw scanning and exploitation attempts against US financial institutions, defense contractors, and military organizations, as well as government networks in Europe, Asia, and Africa. Researchers spotted attacks against 12 IP addresses associated with U.S. federal agencies and 11 with those of local or state governments. Government systems - like those used by the U.K., France, Japan, Australia and India - were also similarly targeted. The activity stopped briefly between October 1 and 8, during China's Golden Week holiday. Unit 42 officials added that "despite multiple advisories published about the group, Storm-1849 persisted in targeting vulnerable government edge devices" and continued to exploit the flaws aggressively. The campaign follows an emergency directive from the U.S. Cybersecurity and Infrastructure Security Agency mandating agencies to patch two critical vulnerabilities in ASA, CVE-2025-30333 and CVE-2025-20362, which hackers have been chaining together for greater impact. Together, these enable attackers to maintain persistence even following system reboots or upgrades. CISA said the bugs could be exploited with “alarming ease,” giving agencies just one day to implement patches. Although CISA and Cisco have avoided direct attribution, several cybersecurity firms-most notably, Censys-have linked the activity to Chinese state-backed actors associated with the 2024 ArcaneDoor campaign. Researchers believe the continued targeting underscores China’s growing cyber-espionage capabilities, and the emergence of new, aggressive groups such as Storm-1849 that are expanding their global reach.