The Australian government has issued a new warning over an ongoing wave of cyberattacks targeting unpatched Cisco IOS XE devices across the country, with attackers deploying the BadCandy webshell to seize control of vulnerable routers.
The exploitation campaign centres on CVE-2023-20198, a critical flaw that allows unauthenticated attackers to create administrative accounts via the web interface and take full control of affected systems.
Cisco addressed the vulnerability in October 2023, but a public proof-of-concept exploit released shortly afterward led to widespread attacks and backdoor installations on internet-exposed devices.
According to the Australian Signals Directorate (ASD), variants of the Lua-based BadCandy webshell have continued to circulate through 2024 and 2025, underscoring that many routers remain unpatched.
Once installed, BadCandy grants attackers root-level command execution, providing unrestricted access to compromised hardware.
While the implant is wiped when a device reboots, attackers can easily reinfect systems if the web interface remains open and the underlying flaw unpatched.
“Since July 2025, ASD assesses over 400 devices were potentially compromised with BadCandy in Australia,” the agency said in a recent bulletin. “As at late October 2025, there are still over 150 devices compromised.”
Although infection numbers have declined, ASD analysts report repeat exploitation of the same endpoints, suggesting adversaries are monitoring for cleanup efforts and swiftly redeploying the malware.
To combat the attacks, the ASD has begun directly notifying affected organisations and working with internet service providers to reach victims whose ownership details are unclear.
The bulletin also notes that state-linked threat groups, including the Chinese-aligned actor Salt Typhoon, have previously exploited the same Cisco vulnerability in campaigns against major telecommunications firms in the U.S. and Canada.
While BadCandy can be deployed by any actor, the ASD believes recent activity shows hallmarks of state-sponsored operations.
Authorities urge all administrators of Cisco IOS XE systems—both in Australia and abroad—to apply Cisco’s security updates immediately and follow the vendor’s mitigation advice to prevent reinfection.

