$ techbeacon▋
Ransomware

Multiple Threat Actors Leverage Cisco FMC Vulnerabilities to Deploy Qilin Ransomware

Multiple Threat Actors Leverage Cisco FMC Vulnerabilities to Deploy Qilin Ransomware

Three separate cyber‑crime groups are actively exploiting two newly disclosed flaws in Cisco's Secure Firewall Management Center (FMC), using the weaknesses to harvest credentials, obtain root privileges and install the Qilin ransomware, Cisco's Talos research team reported.

The vulnerabilities, which were patched by Cisco earlier this month, affect the management interface that administrators use to configure and monitor Cisco firewalls. According to Talos, the flaws allow unauthenticated attackers to bypass authentication mechanisms and execute arbitrary commands on the underlying Linux host, effectively granting full system control.

Despite the availability of patches, the three threat groups have been observed targeting unpatched FMC installations across a range of sectors, including manufacturing, healthcare and education. By stealing privileged credentials and escalating to root, the actors can disable security controls, exfiltrate data and then unleash Qilin ransomware, a payload that encrypts files and demands payment in cryptocurrency.

Qilin ransomware, first identified in 2022, is known for its rapid encryption speed and its use of custom encryption keys that complicate decryption without the attacker’s private key. The recent campaigns suggest the ransomware’s operators are capitalising on the FMC breach to reach organizations that rely heavily on Cisco firewalls for perimeter defense, potentially widening the impact of the attacks.

Cisco has urged all customers to apply the latest FMC updates immediately and to audit any systems that may have been compromised before the patch was released. Security experts also recommend implementing network segmentation, enforcing multi‑factor authentication for management consoles, and monitoring for unusual command‑line activity that could indicate exploitation.

Talos continues to track the activity of the three groups, noting that their tactics align with known ransomware‑as‑a‑service models. Law enforcement agencies have been notified, and further investigations are underway to identify the actors behind the campaigns. As organizations scramble to secure their firewall management infrastructure, the incident underscores the broader challenge of maintaining timely patch management in a landscape where threat actors rapidly weaponise newly disclosed vulnerabilities.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related