In a turn of events, the number of Cisco IOS XE devices that were infected during a zero-day attack last week with the malicious backdoor implant has dropped drastically from roughly 60,000 devices to about 1,200. This caused security researchers to speculate about what happened.
Earlier last week, Cisco issued a warning about hackers exploiting two zero-day vulnerabilities, CVE-2023-20198 and CVE-2023-20273. The attackers used these vulnerabilities to establish privileged user accounts and install a malicious LUA backdoor implant. This LUA implant allows the threat actors to remotely execute commands at the highest privilege level, which is level 15 on the device.
However, the implanted backdoor lacks persistence, meaning a simple device reboot would remove the malicious code. Local user accounts created during the attack would still remain intact, giving customers an easy workaround to avoid the issue. Cisco has also since released a patch to the issues.
An analysis of the exploit by security researcher Daniel Card, suggests the devices breached in the hack were merely a smoke screen to hide the real targets. According to him, the threat actors using did not exploit all of the ~140,000 exposed servers.
“Let’s be honest: if you shell 20-40K devices why would your kill chain stop at that device?” he asked in a thread about the exploit on X. According to his analysis, the end of the exploit was not for financial gain, but more likely espionage.
The theory remains that this decline in numbers could still be attributed to a massive mistake. “Was this a f**kup? Was this an intentional move to hide the real targets? That’s a good f**king ruse if so,” he said.
Recommended
- Google’s Project Zero Uncovers Major iPhone Security Flaw
- Cisco to Provide Cyber Security Training to 120,000 UK Police Officers
- Cisco Partners with Edinburgh University to Drive Data Innovation
If it were a mistake, the threat actors could be deploying an update to conceal their presence. Founder and CTO of Onyphe told BleepingComputer: “We believe it is the action from the original threat actor which is trying to fix an issue that should not have been there from the beginning. The fact that the implant was so easy to detect remotely was a mistake from their side. They are probably deploying an update to hide their presence.”
Whether or not this was a mistake, cyber-defence firm CERT Orange said: “we have to assume that equipments where the implant was here till yesterday – but no longer today, are still corrupt – and are maybe in another exploitation stage,” in a post on X.
At this time, these are just theories as Cisco has yet to clarify the decrease in implants.





