BadCandy campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed October 31, 2025; most recent activity October 31, 2025.
BadCandy is a threat campaign that deploys implants on compromised devices to maintain persistence and control. A recent report indicates hundreds of Australian devices have been compromised by a BadCandy implant, underscoring ongoing activity and the campaign's scale in 2025.
Cyberattacks exploiting a critical vulnerability in Cisco IOS XE (CVE-2023-20198) continue, with over 150 devices in Australia still infected with the BadCandy webshell as of late October 2025. Despite patches being…
The Australian government has issued a warning about ongoing cyberattacks exploiting CVE-2023-20198, a critical vulnerability in Cisco IOS XE devices. As of late October 2025, over 150 devices in Australia remain…