Prior to July 2026, an advanced persistent threat (APT), which overlaps in tactics, techniques, and procedures (TTPs) with Salt Typhoon, compromised a North American hydroelectric organization's internet-facing Cisco router by exploiting known Cisco IOS XE WebUI vulnerabilities (CVE-2023-20198 and CVE-2023-20273 ). The threat actor then deployed a webshell and created highly privileged accounts. They manipulated network device configurations to disable logging, downgrade encryption, and alter routing paths to evade detection. The threat actors established a hidden protocol tunnel to securely exfiltrate VPN configurations to an external command-and-control server. This activity highlights a significant espionage or pre-positioning threat to critical infrastructure.
Critical infrastructure organizations who considered valuable targets to APT groups are encouraged to inspect Cisco router configuration files for the presence of the BadCandy implant, changes to configuration files, deletion or disabling of logging, creation of accounts or elevation of account privileges, and relocation of web management to port 10808 or other high-level ports with HTTPS disabled. Additionally, ensure that all systems – particularly internet-accessible systems – are up to date with the latest patch levels.

