Cisco Email Security Appliances Compromised by Chinese Threat Group Using CVE-2025-20393
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Cisco has reported that a threat group linked to China has been exploiting vulnerabilities in Cisco email security appliances since at least late November 2025. The attackers utilized CVE-2025-20393, a flaw related to improper input validation, allowing them to execute arbitrary commands with root privileges without authentication. This campaign specifically targeted Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances that had the Spam Quarantine feature configured to be accessible from the internet.
The attack was discovered on December 10 during a support case resolution, leading to an investigation that revealed the installation of several malicious tools, including AquaShell, AquaPurge, AquaTunnel, and Chisel. These tools enabled the attackers to maintain control over the compromised appliances and erase logs to cover their tracks.
Currently, it is unclear how many devices have been affected by this campaign. Cisco has indicated that the Spam Quarantine feature is not enabled by default, and their deployment guides do not require the associated port to be exposed to the internet. Organizations using these appliances are urged to review their configurations to prevent unauthorized access.
In light of this incident, organizations should be aware of the potential risks associated with misconfigured security appliances. The use of custom-made malware by sophisticated threat actors highlights the need for robust security practices and regular audits of device configurations.
As the investigation continues, Cisco is expected to release a patch for CVE-2025-20393 soon. In the meantime, organizations should follow Cisco’s recommendations to secure their appliances and consider rebuilding any compromised devices to eliminate the threat actors’ persistence mechanisms.
Key Takeaways
- Check whether your Cisco email security appliances have the Spam Quarantine feature enabled and exposed to the internet.
- Contact Cisco Technical Assistance Center if you suspect your appliance has been compromised.
- Prepare to rebuild affected appliances to remove any installed backdoors.
- Regularly review and update your security configurations to prevent unauthorized access.
- Stay informed about the upcoming patch for CVE-2025-20393 and apply it promptly.
Key Terms & Concepts
- CVE-2025-20393: In this article, CVE-2025-20393 refers to a vulnerability in Cisco email security appliances that allows unauthorized command execution.
- AquaShell: AquaShell is a custom-made Python backdoor used by attackers to maintain control over compromised Cisco appliances.
- Spam Quarantine: Spam Quarantine is a feature in Cisco email security appliances that can be configured to manage spam messages.
- Chinese-nexus threat group: This term refers to a group of threat actors believed to be linked to Chinese cyber operations, involved in sophisticated attacks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.