Cisco Talos has discovered an ongoing campaign exploiting a critical zero-day vulnerability in Cisco AsyncOS Software affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
The flaw allows attackers to execute system-level commands remotely and deploy sophisticated backdoors on compromised systems, posing a significant threat to enterprise email security infrastructure.
The attack campaign is attributed to UAT-9686, assessed with moderate confidence to be a Chinese-nexus advanced persistent threat group.
Cisco identified the malicious activity on December 10, 2025, though evidence suggests attacks commenced in late November 2025, potentially affecting organizations for weeks without detection.
Sophisticated Attack Toolkit
The threat actors employ a multi-stage attack framework that includes custom-developed tools for persistence and lateral movement.
AquaShell, a lightweight Python backdoor, represents the core persistence mechanism. This malware embeds itself into existing files within Python-based web servers and listens for unauthenticated HTTP POST requests containing specially crafted data.

The backdoor decodes incoming commands using custom algorithms combined with Base64 decoding before executing them on compromised appliances.
Complementing AquaShell, UAT-9686 deploys AquaTunnel, derived from the open-source ReverseSSH backdoor.
This tool establishes reverse SSH connections from compromised systems to attacker-controlled servers, enabling persistent unauthorized access even when systems operate behind firewalls.
Chisel, another tunneling utility, allows attackers to proxy traffic through compromised edge devices and facilitate pivot attacks into internal networks.
To cover their tracks, the threat actors utilize AquaPurge. This log sanitization tool removes incriminating evidence by clearing specific keywords from log files using the egrep command, making forensic investigation considerably more difficult.
Cisco Talos identified significant overlaps between UAT-9686 and other known Chinese-nexus threat actors in tactics, techniques, procedures, infrastructure, and victimology.
The tooling, particularly AquaTunnel, aligns with previously attributed Chinese APT groups, including APT41 and UNC5174.
The deployment of custom-made web-based implants, such as AquaShell, is increasingly characteristic of sophisticated Chinese-nexus APT operations.
Analysis indicates that appliances with non-standard configurations remain primarily vulnerable to this attack.
Cisco has published comprehensive security advisories detailing vulnerable systems and mitigation strategies.
Organizations running Cisco Secure Email Gateway or Cisco Secure Email and Web Manager should immediately review Cisco’s official security advisories and check for connections to published indicators of compromise.
Cisco TAC recommends opening support cases if suspicious activity is detected. All associated IOCs have been blocked across the Cisco product portfolio, though organizations should maintain vigilance for potential related threats.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.