Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Ongoing Cyberattacks Target Unpatched Cisco IOS XE Devices With ‘BadCandy’ Webshel
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > Ongoing Cyberattacks Target Unpatched Cisco IOS XE Devices With ‘BadCandy’ Webshel
Cyber

Ongoing Cyberattacks Target Unpatched Cisco IOS XE Devices With ‘BadCandy’ Webshel

The Australian government has issued a warning over ongoing cyberattacks targeting unpatched Cisco IOS XE devices. The attacks are deploying the ‘BadCandy’ webshell to compromise routers and gain remote control.

Editorial Desk
Last updated: November 5, 2025 6:43 pm
Editorial Desk
Share
SHARE

The Australian government has issued a new warning over an ongoing wave of cyberattacks targeting unpatched Cisco IOS XE devices across the country, with attackers deploying the BadCandy webshell to seize control of vulnerable routers.

The exploitation campaign centres on CVE-2023-20198, a critical flaw that allows unauthenticated attackers to create administrative accounts via the web interface and take full control of affected systems.

Cisco addressed the vulnerability in October 2023, but a public proof-of-concept exploit released shortly afterward led to widespread attacks and backdoor installations on internet-exposed devices.

According to the Australian Signals Directorate (ASD), variants of the Lua-based BadCandy webshell have continued to circulate through 2024 and 2025, underscoring that many routers remain unpatched.

Once installed, BadCandy grants attackers root-level command execution, providing unrestricted access to compromised hardware.

While the implant is wiped when a device reboots, attackers can easily reinfect systems if the web interface remains open and the underlying flaw unpatched.

“Since July 2025, ASD assesses over 400 devices were potentially compromised with BadCandy in Australia,” the agency said in a recent bulletin. “As at late October 2025, there are still over 150 devices compromised.”

Although infection numbers have declined, ASD analysts report repeat exploitation of the same endpoints, suggesting adversaries are monitoring for cleanup efforts and swiftly redeploying the malware.

To combat the attacks, the ASD has begun directly notifying affected organisations and working with internet service providers to reach victims whose ownership details are unclear.

The bulletin also notes that state-linked threat groups, including the Chinese-aligned actor Salt Typhoon, have previously exploited the same Cisco vulnerability in campaigns against major telecommunications firms in the U.S. and Canada.

While BadCandy can be deployed by any actor, the ASD believes recent activity shows hallmarks of state-sponsored operations.

Authorities urge all administrators of Cisco IOS XE systems—both in Australia and abroad—to apply Cisco’s security updates immediately and follow the vendor’s mitigation advice to prevent reinfection.

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article AI Governance Still Needs To Mature Australian Security Leaders Optimistic About AI, But Say Governance Still Needs To Mature
Next Article Wearing Too Many Hats Business Why Wearing Too Many Hats Is Killing Australian Businesses
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Cisco IOS XE Devices BadCandy

Tech Articles

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

How some of the internet’s best independent blogs were quietly…

June 3, 2026
The Decay of guest blogging posts

The Decay of Guest Blogging. It Got Cheap, Automated, and Spammy.

Guest blogging once helped publishers showcase real expertise and build…

June 9, 2026
Top Big Tech Companies 2026

The Big Tech Companies Actually Winning In 2026 — And Numbers That Prove It

Top tech companies in 2026 included AppLovin, AWS, Microsoft, Meta,…

May 20, 2026

Recent News

AFP Medibank data breach russian hackers
Cyber

AFP Points The Finger At Russian Hackers For Medibank Data Breach

2 Min Read
Gov flags new rules after Optus hack
Cyber

Federal Government Prepares New Data Breach Notification Rules After Optus Hack.

2 Min Read
Cyber-crime gangs' earnings drop
Cyber

Cyber-Crime Gangs Earnings See 40% Drop as Business Owners Refuse to Pay Ransom Demands

2 Min Read
Mandaint changes to Fireeye
Cyber

Mandiant Confirms Name Change from FireEye, Inc. to Mandiant, Inc.

3 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

August, 11, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?