Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-9686

Also known as: tracked as, UAT 9686, AquaTunnel, Chisel, AquaPurge, AquaShell, ReverseSSH, UNC5174, UNC-9686, CVE-2025-20393, Silence.Downloader

Description

UAT‑9686 is an advanced threat actor linked to China that has been actively targeting Cisco AsyncOS Software used in secure email gateways and web manager appliances since late November 2025. The campaign exploits CVE‑2025‑20393, a remote code execution vulnerability triggered through the Spam Quarantine feature of exposed appliances. Once access is achieved, the group deploys AquaShell—a Python‑based web shell that accepts encoded HTTP POST requests—to obtain full root privileges and execute arbitrary commands on the host. To maintain persistence and evade detection, UAT‑9686 installs reverse tunneling utilities such as AquaTunnel (a Go‑Lang based ReverseSSH implementation) and Chisel, establishing outbound SSH tunnels back to attacker-controlled infrastructure. The actor also deploys AquaPurge, a tool designed to clear system logs, thereby erasing forensic evidence of the intrusion. These capabilities collectively enable coordinated manipulation of critical communication channels while keeping the foothold hidden. Talos analysis indicates operational overlap with other Chinese‑nexus groups such as APT41 and UNC5174, suggesting shared tooling and methodology. The persistence mechanisms show a methodical approach to compromising edge devices that serve as entry points into larger enterprise networks.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Financial services
Defense
Telecommunications
Healthcare
Media
Non profit
Energy
Education
Nuclear
Utilities
Manufacturing

Targeted Countries / Regions

CN
RU
UA
US
GB
IL
FR
DE
IR
PL
EG
RO

AI Analysis

Grounded in web research
· 3 hours ago

Executive Summary

UAT‑9686 is a Chinese‑linked APT that leveraged the zero‑day CVE‑2025‑20393 to compromise Cisco AsyncOS appliances in secure email gateways worldwide. The group deploys a lightweight Python backdoor (AquaShell), reverse SSH tunnels (AquaTunnel and Chisel) and log‑clearing utilities (AquaPurge) to maintain stealth and control over compromised edge devices.

Goals & Targeting

UAT‑9686’s strategic objective is to gain persistent remote access to high‑value networking infrastructure, exploiting vulnerabilities in Cisco Secure Email Gateway appliances used by governments, critical infrastructure providers, and large enterprises worldwide. By installing backdoors and establishing reverse tunnels on these edge devices, the actor can covertly exfiltrate data or pivot into broader corporate networks for espionage, sabotage, or later monetary exploitation. Typical victims are organizations that own or operate Cisco Secure Email Gateway and Web Manager appliances—often in sectors such as finance, defense, utilities, healthcare, and education across countries including CN, RU, UA, US, GB, IL, FR, DE, IR, PL, EG, and RO.

Enhanced Description

Key Capabilities

  • Exploitation of zero‑day RCE CVE-2025-20393 via Spam Quarantine interface
  • Deployment of lightweight Python web shell AquaShell for command execution
  • Establishment of reverse SSH tunnels using AquaTunnel (ReverseSSH) and Chisel
  • Log clearing and defense evasion with AquaPurge
  • Persistent remote control over compromised appliances
  • Use of custom encoding/decoding routines to hide payloads

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Command and Control

ATT&CK Techniques

T1190 - Exploit Public-Facing Application
T1203 - Exploit for Client Execution
T1068 - Exploitation for Privilege Escalation
T1059.003 - Command and Scripting Interpreter: Unix Shell
T1562.004 - Impair Defenses

Software / Tooling

AquaShell
AquaTunnel (ReverseSSH)
Chisel
AquaPurge
Custom web shell implants
Python-based payloads

Campaigns & Victims

The UAT‑9686 campaign has operated with high tempo since November 2025, coinciding with the discovery of CVE-2025-20393. The actor systematically scans for Cisco AsyncOS appliances with Spam Quarantine enabled, exploits the vulnerability remotely, and deploys its toolset to secure a foothold and maintain anonymity through reverse tunnels and log deletion. Victim organizations reflect the broad reach of Cisco Edge devices across many critical sectors, and the campaign exhibits clear patterns of leveraging a single high‑impact exploit followed by disciplined post‑compromise procedures. No public evidence currently links financial gain objectives directly; however, the potential for data exfiltration or later monetization remains. Notable past operations include documented compromises reported to Cisco in December 2025 and subsequent advisories issued by CISA, indicating a coordinated effort against federal agencies and international enterprises.

IOC Patterns

  • Exploit of CVE-2025-20393 via Spam Quarantine interface
  • Unauthenticated HTTP POST requests containing encoded commands for AquaShell execution
  • Reverse SSH tunneling using AquaTunnel or Chisel to attacker-hosted servers
  • Log clearing operations with AquaPurge on compromised devices
  • Persistence through embedded Python backdoor in web server files

Recommended Actions

  • Apply updated firmware or software patches for Cisco AsyncOS appliances as soon as they are released; until then, restrict inbound access to Spam Quarantine interfaces via firewalls and segmentation.
  • Disable or tightly configure the Spam Quarantine feature if it is not essential. Monitor network traffic for anomalous outbound SSH connections, especially reverse tunnels originating from known Cisco device IPs. Deploy host‑based intrusion detection that flags unknown Python executables or unusual modifications to web server files. Enable detailed logging on appliances and centralize logs in a tamper‑evident SIEM; regularly audit for missing entries indicative of AquaPurge usage. Use Web Application Firewalls (WAF) with custom rules to detect malformed HTTP POST payloads targeting the web shell API endpoints.
  • suggested_tags
  • APT
  • Chinese-nexus
  • State-sponsored
  • Espionage
  • Critical-infrastructure-attacks
  • Email-Gateway-Compromise
  • Zero-Day-Exploit
  • Remote-Code-Execution
  • Command-and-Control

Confidence Assessment

Information is derived primarily from Cisco Talos, Cisco security advisories and CISA alerts, providing a moderate level of confidence regarding the technical details of UAT‑9686’s methodology. The attribution to a Chinese state-sponsored actor remains at analytic inference based on shared tooling patterns; further data is needed for definitive attribution. Key gaps include precise operation dates, broader campaign scope beyond Cisco AsyncOS appliances, and direct evidence linking the group’s activities to financial outcomes.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: ReverseSSH
  2. www.esentire.com — Cited by web research for: UNC-9686
  3. www.greenbone.net — Cited by web research for: CVE-2025-20393
  4. attack.mitre.org — Cited by web research for: Interception
  5. blog.talosintelligence.com — Cited by web research for: Global
  6. cert.europa.eu — Cited by web research for: BRICKSTORM
  7. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 — Cited by AI analysis.
  8. https://nvd.nist.gov/vuln/detail/CVE-2025-20393 — Cited by AI analysis.
  9. https://www.cisa.gov/news-events/alerts/2025/12/17/cisa-adds-three-known-exploited-vulnerabilities-catalog — Cited by AI analysis.

Intel Summary

10

Techniques

47

Tools

0

Campaigns

11

IOCs

0

Observed Data

4

Tactics

Tags

APT
Critical Infrastructure
Espionage
Networking Infrastructure
Cisco
State-sponsored

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.