Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
30APR

Federal agency stayed compromised six months

3 min read
08:16UTC

An unnamed US federal agency was confirmed still hosting FIRESTARTER in March 2026, six months after applying the September 2025 Cisco patches.

TechnologyDeveloping
Key takeaway

Six months of dwell after a clean patch shifts the lever from SLA compliance to forensic audit.

CISA disclosed alongside the FIRESTARTER advisory that an unnamed US federal agency was confirmed still hosting the implant in March, six months after the September patch cycle that should have closed the file 1. The agency had applied those patches on schedule and the implant rode through. CISA has not released the agency's identity.

The operational read of the implant's design explains the dwell. UAT-4356's FIRESTARTER writes itself back to disk before clean shutdowns, so a routine patch reboot reinstates the backdoor rather than removing it. There is no continuous outbound beacon to flag in network telemetry; activation runs through magic-packet primitives that look like ordinary WebVPN traffic until the secret prefix arrives. NCSC and CISA are, in effect, telling operators that the September patch cycle is not a closure event but a starting line for memory analysis and device-side anomaly detection.

BRICKSTORM sets the precedent that frames this dwell. Mandiant disclosed BRICKSTORM at much longer residency than the FIRESTARTER federal case, which signals that nation-state actors are confident they will be undetected long enough to amortise the implant cost across multiple operational objectives. The implication for any CISO with Cisco ASA or FTD at the edge is a procurement audit on attestation and immutable-boot product categories, plus a board-level conversation about disclosure exposure when 'patched' and 'clean' have decoupled.

Deep Analysis

In plain English

A US government agency followed all the official advice: it applied the security patches, ticked every compliance box, and signed off the firewall as clean. Months later it turned out the firewall still contained a hidden back door that the patch had simply left untouched. This happened because the patch fixes software; the back door had hidden itself below the level software controls, in the code that runs before any software starts. Compliance paperwork and real-world cleanliness had silently separated.

Deep Analysis
Root Causes

Standard enterprise patch management operates on a compliance model: apply the patch, record the completion, close the ticket. This model assumes that applying a patch to a device is equivalent to removing a prior compromise, which is structurally false for boot-sequence implants that restore themselves before the OS loads.

The unnamed federal agency's six-month dwell also exposes a monitoring gap specific to network-edge devices. Most SOC tooling is designed for endpoint and cloud workload telemetry; firewall appliances are monitored primarily via syslog and SNMP for availability, not for sub-OS anomaly detection.

FIRESTARTER produced no continuous beacon and activated only on the specific magic-packet trigger, which means no traffic anomaly appeared in the monitoring layer until CISA's external detection process identified the device.

What could happen next?
  • Consequence

    Federal contractor and critical infrastructure operators subject to FISMA or NIS2-equivalent frameworks face a disclosure question: 'patched and compliant' is no longer a sufficient answer to board-level incident materiality review.

    Immediate · 0.85
  • Risk

    SOC tooling vendors face pressure to add device-level boot-sequence anomaly detection as a default capability; current SIEM and EDR products have no visibility below the OS layer on firewall appliances.

    Short term · 0.8
  • Precedent

    CISA's decision to disclose a specific federal dwell figure sets a new bar for government transparency on active compromises; prior practice was to confirm breaches without releasing forensic detail.

    Medium term · 0.75
First Reported In

Update #2 · FIRESTARTER puts Cisco below the patch line

CISA· 30 Apr 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.