Amazon’s threat intel team identified an advanced threat actor leveraging two zero‑day vulnerabilities—CVE‑2025‑20337 in Cisco Identity Services Engine and CVE‑2025‑5777 in Citrix NetScaler ADC—to deploy a custom in‑memory Java web shell targeting Cisco ISE appliances.
The activity was first flagged by Amazon’s MadPot honeypot network. Analysts observed exploit attempts against CVE‑2025‑5777 and CVE‑2025‑20337, followed by delivery of a custom back‑door named IdentityAuditAction. The web shell runs entirely in memory, uses Java reflection, registers a listener on the Tomcat server, and encrypts traffic with DES and a non‑standard Base64 encoding. Amazon attributes the campaign to a highly resourced actor with zero‑day capability and knowledge of enterprise Java and network‑edge appliances.
Apply the vendor‑released patches for CVE‑2025‑20337 (Cisco) and CVE‑2025‑5777 (Citrix) immediately. Restrict network access to management interfaces using firewalls, VLAN segmentation, and zero‑trust controls. Deploy host‑based intrusion detection to monitor unexpected Java processes, Tomcat modifications, and abnormal HTTP traffic. Enable multi‑factor authentication for administrative accounts and regularly audit privileged access.
Patch vulnerable Cisco ISE and Citrix NetScaler devices, isolate compromised systems, and remove the custom web shell. Conduct forensic analysis of logs and memory dumps to identify indicators of compromise. Update detection rules in SIEM and IDS/IPS for the exploit payloads and web‑shell signatures. Notify relevant stakeholders and, if required, report the incident to appropriate authorities.
Simulation Execution Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.
Attack Narrative & Commands:
Execution Trigger: The attacker sends a forged HTTP request that causes the ISE process to launch the servlet, resulting in a command line similar to:
Regression Test Script:
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
