Also known as: tracked as, UAT 9686, AquaTunnel, Chisel, AquaPurge, AquaShell, ReverseSSH, UNC5174, UNC-9686, CVE-2025-20393, Silence.Downloader
UAT‑9686 is an advanced threat actor linked to China that has been actively targeting Cisco AsyncOS Software used in secure email gateways and web manager appliances since late November 2025. The campaign exploits CVE‑2025‑20393, a remote code execution vulnerability triggered through the Spam Quarantine feature of exposed appliances. Once access is achieved, the group deploys AquaShell—a Python‑based web shell that accepts encoded HTTP POST requests—to obtain full root privileges and execute arbitrary commands on the host. To maintain persistence and evade detection, UAT‑9686 installs reverse tunneling utilities such as AquaTunnel (a Go‑Lang based ReverseSSH implementation) and Chisel, establishing outbound SSH tunnels back to attacker-controlled infrastructure. The actor also deploys AquaPurge, a tool designed to clear system logs, thereby erasing forensic evidence of the intrusion. These capabilities collectively enable coordinated manipulation of critical communication channels while keeping the foothold hidden. Talos analysis indicates operational overlap with other Chinese‑nexus groups such as APT41 and UNC5174, suggesting shared tooling and methodology. The persistence mechanisms show a methodical approach to compromising edge devices that serve as entry points into larger enterprise networks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑9686 is a Chinese‑linked APT that leveraged the zero‑day CVE‑2025‑20393 to compromise Cisco AsyncOS appliances in secure email gateways worldwide. The group deploys a lightweight Python backdoor (AquaShell), reverse SSH tunnels (AquaTunnel and Chisel) and log‑clearing utilities (AquaPurge) to maintain stealth and control over compromised edge devices.
Goals & Targeting
UAT‑9686’s strategic objective is to gain persistent remote access to high‑value networking infrastructure, exploiting vulnerabilities in Cisco Secure Email Gateway appliances used by governments, critical infrastructure providers, and large enterprises worldwide. By installing backdoors and establishing reverse tunnels on these edge devices, the actor can covertly exfiltrate data or pivot into broader corporate networks for espionage, sabotage, or later monetary exploitation. Typical victims are organizations that own or operate Cisco Secure Email Gateway and Web Manager appliances—often in sectors such as finance, defense, utilities, healthcare, and education across countries including CN, RU, UA, US, GB, IL, FR, DE, IR, PL, EG, and RO.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The UAT‑9686 campaign has operated with high tempo since November 2025, coinciding with the discovery of CVE-2025-20393. The actor systematically scans for Cisco AsyncOS appliances with Spam Quarantine enabled, exploits the vulnerability remotely, and deploys its toolset to secure a foothold and maintain anonymity through reverse tunnels and log deletion. Victim organizations reflect the broad reach of Cisco Edge devices across many critical sectors, and the campaign exhibits clear patterns of leveraging a single high‑impact exploit followed by disciplined post‑compromise procedures. No public evidence currently links financial gain objectives directly; however, the potential for data exfiltration or later monetization remains. Notable past operations include documented compromises reported to Cisco in December 2025 and subsequent advisories issued by CISA, indicating a coordinated effort against federal agencies and international enterprises.
IOC Patterns
Recommended Actions
Confidence Assessment
Information is derived primarily from Cisco Talos, Cisco security advisories and CISA alerts, providing a moderate level of confidence regarding the technical details of UAT‑9686’s methodology. The attribution to a Chinese state-sponsored actor remains at analytic inference based on shared tooling patterns; further data is needed for definitive attribution. Key gaps include precise operation dates, broader campaign scope beyond Cisco AsyncOS appliances, and direct evidence linking the group’s activities to financial outcomes.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
47
Tools
0
Campaigns
11
IOCs
0
Observed Data
4
Tactics