Gridware Logo

Routers at Risk: BADCANDY Cyber Threat

By Ahmed Khanji Updated 13 November 2025 4 min read

in 𝕏
Routers at Risk: BADCANDY Cyber Threat

Australia’s BADCANDY Problem | The Cisco Exploit Still Active in 2025

The Australian Signals Directorate (ASD) has warned that hundreds of Australian networks have been affected by a malicious implant known as BADCANDY.

The implant targets Cisco IOS XE devices and allows attackers to take full control of a system.

These devices are common in:

  • Routers that manage traffic between offices or data centres
  • Switches that connect internal networks
  • Firewalls and edge gateways that link organisations to the internet

They form the backbone of many business networks, which is why a compromise here can expose entire systems.

More than 400 devices were found to be compromised between July and October 2025. While that number has dropped, more than 150 remain infected. Throughout 2025, edge devices have been one of the weakest points in corporate and government networks.

What is BADCANDY

BADCANDY is a small, hidden web shell written in Lua that installs itself on vulnerable Cisco devices.

Lua is a scripting language often built into network devices. It’s designed to automate simple functions, but attackers can use it to run hidden commands once they gain access.

It exploits CVE-2023-20198, a flaw in Cisco’s web user interface. It came from how the system processed browser requests, letting attackers create new administrator accounts without needing a password.

The implant can hide its presence by applying a temporary patch that makes the system appear secure, even while compromised. It stays active until the device is rebooted, which removes the implant from memory but not from the attacker’s reach.

If credentials or network paths were already taken, they can still be used to get back in

How It Spread

Since 2023, several threat actors have been exploiting the same Cisco weakness.

Activity linked to Salt Typhoon, a known Chinese state backed group, has been tied to earlier waves of the attack.

The implant reappeared in 2024 and again through 2025 as attackers started scanning the internet for exposed Cisco devices that were still unpatched.

ASD found that many of the affected systems were compromised repeatedly after being cleaned. Once attackers detected that the BADCANDY implant was removed, they just reinstalled it on unpatched devices almost immediately.

Where the Situation Stands Now

BADCANDY infections detected across Australia, July–October 2025. (Source: ASD)

ASD’s data shows that infections rose and fell through 2025, often dropping after alerts were sent to affected organisations.

Who’s Behind It

ASD believes both criminal and state sponsored groups are using the implant.

Their goal is generally persistence rather than damage, meaning they want to stay hidden inside infrastructure for as long as possible.

By exploiting network edge devices, attackers can gain quiet access to internal systems without alerting central monitoring tools.

What Organisations Should Do

Any business or agency running Cisco IOS XE should act quickly:

If you don’t know whether your organisation uses Cisco devices, check with your IT or network provider.

  1. Patch immediately for CVE-2023-20198 using Cisco’s latest update.
  2. Reboot the device after patching to clear any implant from memory.
  3. Review admin accounts and remove any that look unfamiliar, especially names like “cisco_tac_admin” or random strings.
  4. Check for tunnels or new configurations that were not created internally.
  5. Restrict access to the web interface or disable it completely if it’s not required.
  6. Audit logs for any changes that took place before or after the patch.

Resources to Check Out

  • Cisco has an IOS XE Hardening Guide that explains how to secure affected devices and reduce exposure.
  • ASD’s Securing Edge Devices guide walks through simple ways to lock down devices that connect your network to the internet.

If you’re not sure where to begin, Gridware’s Cybersecurity Complete Guide covers how to check your setup and strengthen it over time.

And if you’d rather have someone take a closer look, our Cybersecurity Audit and Assessment service can help review your systems and confirm your devices are secure.

Why This Still Matters

Even though the implant itself disappears after a reboot, any stolen credentials or network paths can continue to expose an organisation.

The problem is less about malware and more about control. Once attackers have a way in, they can return as often as they like until the source vulnerability is closed.

Edge device exploitation has become one of the fastest growing intrusion points in Australia.

Organisations that treat routers and gateways as part of their active security posture are much more likely to detect and contain these breaches early.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.