Halloween
– Getty Images

Australia’s security authority has warned Cisco users of a particularly sour implant vulnerability.

Dubbed BadCandy, the implant affects Cisco IOS XE devices with a basic web shell based on Lua coding. The attack takes advantage of an existing vulnerability, CVE-2023-20198, which allows bad actors to create an administrator account on said devices.

First discovered in 2023, the Cisco-based flaw has seen use by Salt Typhoon, the People’s Republic of China (PRC)-affiliated hacking group blamed for what was dubbed the worst telecom breach in U.S. history last year.

In a warning issued on Halloween, the Australian Signals Directorate (ASD) reported more than 150 devices were compromised with BadCandy in Australia, following an initial breach of 400 reported in July.

“The BadCandy implant does not persist following a device reboot; however, where an actor has accessed account credentials or other forms of persistence, the actor may retain access to the device or network,” wrote ASD. “The patch for CVE-2023-20198 must be applied to prevent re-exploitation. Access to the web user interface should also be restricted if enabled.”

The security agency said it had sent recommendations to compromised entities via their service provider when unable to determine the system operator, and will continue to conduct victim notifications to ensure system operators are aware of any breaches.

ASD warned that criminal and state-sponsored actors like Salt Typhoon may utilize the BadCandy implant, posing an ongoing risk to Australian networks.

“ASD believes actors are able to detect when the BadCandy implant is removed and are re-exploiting the devices. This further highlights the need to patch against [the vulnerability] to avoid re-exploitation,” it added.

While BadCandy first surfaced in 2023, the Australian resurgence follows recent flaws to strike at Cisco security.

Last month saw attackers breach Cisco switch kits, allowing for remote code execution and persistent unauthorized access.

The exploit came days after Cisco was pressed by U.S. Senator Bill Cassidy (R-LA) over a separate exploit in its firewall offerings that may have allowed for a nation-state backed breach.

The attacks, which take advantage of a remote code execution vulnerability (CVE-2025-20333) and a privilege escalation flaw (CVE-2025-20362), have been linked to the ArcaneDoor campaign, which Cisco reported on early last year.