AquaShell is a lightweight Python-based backdoor deployed on compromised Cisco Secure Email Gateway and Secure Email and Web Manager appliances running AsyncOS. It is embedded into web-server components and operates as a passive listener, accepting encoded commands through unauthenticated HTTP POST requests and executing them in the underlying system shell. The malware provides persistent command execution on compromised appliances. AquaShell was observed in exploitation of CVE-2025-20393, an AsyncOS Spam Quarantine vulnerability enabling unauthenticated root-level command execution on exposed, affected appliances. Cisco Talos tracked AquaShell as part of activity associated with the China-nexus threat actor UAT-9686; accompanying tooling included reverse-tunneling and log-clearing utilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In December 2025, Cisco disclosed CVE-2025-20393, a maximum-severity (CVSS 10.0) AsyncOS flaw in Secure Email Gateway and Secure Email and Web Manager appliances. Exploitation was assessed with moderate confidence as conducted by the Chinese-nexus actor UAT-9686. | “AquaShell, a persistent Python backdoor; AquaTunnel and Chisel for reverse SSH tunneling; AquaPurge, a log-clearing utility to erase the evidence.”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“AquaShell, a persistent Python backdoor; AquaTunnel and Chisel for reverse SSH tunneling; AquaPurge, a log-clearing utility to erase the evidence.”
Cisco observed that successful exploitation of the vulnerability resulted in the deployment of the custom webshell AquaShell, a Python-based backdoor capable of receiving and executing encoded commands in the system shell.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Podľa skupiny Cisco Talos zraniteľnosť zneužíva čínska skupina UAT‑9686 pri nasadzovaní perzistentných zadných dvierok AquaShell...
Cisco observed that successful exploitation of the vulnerability resulted in the deployment of the custom webshell AquaShell
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent Python backdoor deployed on Cisco AsyncOS appliances compromised through CVE-2025-20393.
Lightweight Python backdoor that accepts encoded commands via unauthenticated HTTP POST and executes them in the system shell; linked by Talos to UAT-9686.
Lightweight Python backdoor used post-exploitation to receive and execute base64-encoded commands, enabling flexible C2 on compromised Cisco email security appliances.
Custom-made Python backdoor installed on compromised Cisco Email Security appliances to provide attacker access/persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.