AquaShell is a lightweight Python backdoor used to maintain persistence on compromised Cisco AsyncOS appliances, particularly Cisco Secure Email Gateway and Cisco Secure Email and Web Manager systems. It has been associated with exploitation of CVE-2025-20393 by the China-nexus threat actor UAT-9686, which Cisco Talos assessed with moderate confidence as an advanced persistent threat. The malware has been observed as a post-exploitation implant on a limited subset of internet-exposed appliances with Spam Quarantine enabled under non-standard configurations.
AquaShell functions as a covert command-execution backdoor. It is capable of receiving encoded commands through unauthenticated HTTP POST requests and executing them in the system shell, providing attackers with persistent remote access and flexible post-compromise control. Reporting also describes it as embedded into AsyncOS web components to blend with legitimate appliance functionality. In observed campaigns, AquaShell was deployed alongside additional tooling including AquaTunnel or ReverseSSH for reverse tunneling, Chisel for traffic proxying and pivoting, and AquaPurge for log clearing and anti-forensics.
The malware’s operational role is persistence and post-exploitation rather than initial compromise. Initial access in the documented campaign was achieved through exploitation of a critical AsyncOS remote command execution vulnerability, after which AquaShell was installed to preserve access and support follow-on operations. The broader activity aligns with long-term espionage-oriented tradecraft focused on stealth, durable access to edge infrastructure, and concealment of attacker activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-20393 (CVSS skóre 10,0) Kritická zero-day zraniteľnosť zariadení Cisco SEG a Cisco SEWM je aktívna, keď má zariadenie povolenú a do internetu vystavenú funkcionalitu Spam Quarantine. Zraniteľnosť sa nachádza v operačnom systéme Cisco AsyncOS a vzdialený neautentifikovaný útočník by ju mohol zneužiť na vzdialené vykonanie systémových príkazov s oprávneniami root. Zraniteľnosť je aktívne zneužívaná minimálne od konca novembra 2025. | Podľa skupiny Cisco Talos zraniteľnosť zneužíva čínska skupina UAT‑9686 pri nasadzovaní perzistentných zadných dvierok AquaShell...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Podľa skupiny Cisco Talos zraniteľnosť zneužíva čínska skupina UAT‑9686 pri nasadzovaní perzistentných zadných dvierok AquaShell...
3 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lightweight Python backdoor that accepts encoded commands via unauthenticated HTTP POST and executes them in the system shell; linked by Talos to UAT-9686.
Lightweight Python backdoor used post-exploitation to receive and execute base64-encoded commands, enabling flexible C2 on compromised Cisco email security appliances.
Custom-made Python backdoor installed on compromised Cisco Email Security appliances to provide attacker access/persistence.
A custom persistence/backdoor mechanism deployed post-exploitation to maintain long-term access on compromised Cisco Secure Email appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.