Inside a modern data center, showcasing the complex infrastructure powering digital services.
Firestarter Malware Persistence: Cisco Firewalls Affected Despite Patches
Cisco firewall security faces a critical challenge as “Firestarter” malware demonstrates an ability to persist on devices despite the application of security patches. The Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance, recommending a hard reboot for affected Cisco Firepower and Secure Firewall devices to remove the threat.
This development highlights significant concerns regarding Firestarter malware persistence. Standard software updates have proven insufficient against this sophisticated malware.
What Happened
Cisco has confirmed that the ArcaneDoor threat actor deployed a persistence mechanism. This mechanism was not addressed by previous security patches released in September of last year.
The malware affects the operating system in a range of Cisco Firepower and Secure Firewall protective devices. CISA and Britain’s National Cyber Security Centre (NCSC) have named this persistent malware “Firestarter.”
Details From Sources
Malware Characteristics
Firestarter is identified as a Linux binary. The threat actor stowed this Linux binary file within the Firepower eXtensible Operating System (FXOS) base layer.
This placement is crucial because it sits below the software in Firepower Threat Defence (FTD) and Adaptive Security Appliances (ASA). These are the parts customers normally upgrade, allowing Firestarter to survive device reboots.
Persistence Mechanism
The malware employs a complex routine for persistence. Firestarter copies itself to a log directory.
When a firewall receives a graceful termination signal during a reboot, Firestarter rewrites the storage mount list. It points to /usr/bin/lina_cs.
After the reboot, the malware restores the original mount list and removes the trojanised file to hide itself. It also injects itself into the LINA core processing engine on ASA and FTD appliances.
This injection replaces a WebVPN extended markup language handler with a shellcode loader. Firestarter can be triggered by a “magic packet” in an authentication request, effectively acting as a backdoor with remote control abilities. More details are available on Cisco Talos Intelligence Blog.
Remediation Advice
A simple soft reboot will not clear Firestarter malware. CISA advises a hard restart by unplugging firewalls from mains power.
This action interrupts the malware’s persistence routine, as it does not have time to write itself to disk. The Australian Cyber Security Centre (ACSC) has issued a high alert.
ACSC advises organizations to follow CISA’s supplemental direction for emergency directive (ED) 25-03. This involves pulling the plug after a core dump has been collected and submitted. Cisco strongly recommends reimaging and upgrading devices with fixed software releases.
Why This Matters
The criticality of this issue stems from the malware’s ability to persist. It survives despite applied software patches and normal reboots. This persistent threat underscores significant challenges in Cisco firewall security.
The high alert from the ACSC and CISA’s emergency directive highlight the severity of Firestarter malware persistence. Its function as a backdoor with remote control abilities poses a substantial security risk to affected networks.
Background Context
The ArcaneDoor threat actor is responsible for deploying this persistence mechanism. Cisco had released previous security patches related to this actor in September last year. The malicious activity resulting in Firestarter has been in active use since 2024. For more context on ArcaneDoor, refer to Cisco Talos Intelligence Blog.
Industry Reactions
Cybersecurity agencies and Cisco have provided specific actions and advice. CISA and Britain’s NCSC named the malware and detailed its persistent nature.
CISA has directed a hard restart by disconnecting power after collecting a core dump. The ACSC has echoed these warnings with a high alert. Cisco strongly recommends reimaging and upgrading devices with patched software.
Future Implications
CISA is currently investigating the full effects of Firestarter malware on compromised systems.
Conclusion
The Firestarter malware presents a significant persistence challenge for Cisco Firepower and Secure Firewall devices. Despite previous patches, the threat remains active.
Cybersecurity agencies and Cisco recommend urgent measures. These include a hard reboot by unplugging devices and potential reimaging to fully mitigate the threat.
FAQ
Q1: What is Firestarter malware?
A1: Firestarter is a Linux binary malware, named by CISA and NCSC, deployed by the ArcaneDoor threat actor that affects Cisco Firepower and Secure Firewall devices.
Q2: Why is Firestarter malware difficult to remove?
A2: Firestarter malware is difficult to remove because it resides in the Firepower eXtensible Operating System (FXOS) base layer, below standard software upgrades, and has a persistence mechanism that allows it to survive normal device reboots and security patches.
Q3: What remediation steps are advised for Firestarter malware?
A3: CISA advises a hard restart by unplugging affected firewalls from mains power to interrupt the malware’s persistence. Cisco also strongly recommends reimaging and upgrading devices with fixed software releases.
Q4: Which Cisco devices are affected by Firestarter malware?
A4: The operating system in a range of Cisco Firepower and Secure Firewall protective devices is affected, including Firepower Threat Defence (FTD) and Adaptive Security Appliances (ASA).
Q5: Who is the threat actor behind Firestarter malware?
A5: Cisco has confirmed that the ArcaneDoor threat actor deployed the persistence mechanism utilized by Firestarter malware.