RayInitiator Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 2, 2025
Last Seen
April 23, 2026

RayInitiator is a malware family tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity April 23, 2026.

Overview

RayInitiator is a malware family associated with campaigns targeting Cisco ASA firewalls, used to exploit exposed devices and establish footholds within compromised networks. It appears in the context of a broader wave of zero-day and exploit activity against Cisco firewall appliances, with indicators pointing to use by actors scanning and exploiting ASA devices worldwide. The family underscores growing perimeter-device risk and the critical need for rapid patching and monitoring.

Related Threat Clusters

Recent Intelligence Reports

  • US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied — Cyberscoop · April 23, 2026
  • Cisco Firewalls Under Siege: The Escalating Zero-Day Assaults of 2025 — Webpronews · November 8, 2025
  • Cisco Firewalls Under Siege: New Exploits Spark Urgent Patch Warnings — Webpronews · November 6, 2025
  • Chinese Threat Actors Continue To Scan & Exploit Cisco ASA Firewalls Worldwide — Linkedin · November 2, 2025

CVSS v3.1 Breakdown