TL;DR: The week of 18 to 25 December 2025 was dominated by active exploitation of Cisco and Fortinet flaws, alongside Cellik Android RAT’s Play Store trojanization, elevated ransomware claims, and continued targeting of email security gateways, according to FireCompass. The pattern shows why exposed perimeter controls and trusted app channels now create immediate identity and access risk, not just patching debt.
At a glance
What this is: FireCompass’s weekly report highlights active exploitation of critical network flaws, a Play Store trojanized Android RAT, and ransomware activity spikes across the week of 18 to 25 December 2025.
Why it matters: For IAM and security teams, the report matters because perimeter compromise and mobile credential theft both turn trusted access paths into identity problems that affect authentication, escalation, and lateral movement.
By the numbers:
- The week of December 18 to 25, 2025 saw 64 tracked ransomware claims on December 18 alone.
- Qilin accounted for 20.86% of the ransomware ecosystem activity tracked in the report.
- Akira represented 13.9% of the ransomware ecosystem activity tracked in the report.
👉 Read FireCompass's weekly report on active exploitation and critical CVEs
Context
The core issue in this weekly report is not just vulnerability volume, but how quickly attackers convert exposed network devices, trusted gateways, and mobile distribution channels into access paths. In practice, that means identity and access controls are being stressed at the edges of the environment, where credential capture, session abuse, and perimeter compromise can move faster than conventional review cycles. The primary keyword here is active exploitation, and the report shows it is now tightly coupled to identity exposure.
For IAM and NHI practitioners, the useful insight is that perimeter devices, email gateways, and BYOD endpoints all sit inside the same governance problem: who or what is trusted to act, and under what conditions. That makes this a cross-domain security story with a real identity angle, because compromised gateways and trojanized apps can both lead to credential theft, session hijack, and downstream privilege abuse.
Key questions
Q: What breaks when a perimeter appliance is exploited before patching is complete?
A: When an internet-facing gateway is exploited before patching finishes, the trust boundary itself becomes the failure point. Attackers can use the device as an entry path into remote access, session handling, and downstream authentication flows, which means the compromise can outlive the initial vulnerability and affect multiple control layers.
Q: Why do exposed gateways and SSO appliances create so much downstream risk?
A: They sit on privileged traffic paths and often see credentials, tokens, and authenticated sessions in transit. If an attacker controls the device, they may capture secrets, alter access flows, or export configuration data that exposes VPN and firewall trust relationships. That is why these assets carry both infrastructure and identity risk.
Q: How can security teams tell whether mobile trojans are becoming an identity problem?
A: Watch for overlay-driven phishing, unusual permission grants, sideloading attempts, and business logins that coincide with abnormal device behaviour such as camera, microphone, or data spikes. If those signals align, the issue is no longer just malware on a phone. It is a potential account takeover path into enterprise identity systems.
Q: Should organisations prioritise perimeter hardening or mobile controls first?
A: Do both, but prioritise whichever path currently exposes the most privileged access. If external gateways and SSO appliances are internet-facing, hardening them first reduces immediate blast radius. If BYOD is a major access channel, mobile application control and posture enforcement become equally urgent because they protect the credentials users bring into the environment.
Technical breakdown
How active exploitation turns perimeter flaws into identity compromise
Active exploitation matters because a network appliance vulnerability is rarely the final objective. Once an attacker gets root or admin access on a gateway, the device becomes a collection point for traffic, credentials, and sessions. In this report, the Cisco email gateway and Fortinet SSO bypass examples show how a trusted perimeter service can be converted into a credential harvesting and pivoting platform. The technical risk is not only code execution, but the attacker’s ability to observe, redirect, or forge identity assertions.
Practical implication: treat exposed perimeter services as identity-sensitive assets and prioritise patching, segmentation, and configuration hardening.
Why Play Store trojanization changes mobile credential risk
Cellik’s approach shows how attackers can weaponise user trust in legitimate app stores by wrapping malicious payloads inside trojanized APKs. The reported screen streaming, touch simulation, and fake login overlays create a direct path to credential theft and session capture. Because the malware can be distributed through a seemingly normal app workflow, the control problem shifts from simple endpoint scanning to preventing unauthorised app installation and monitoring for abnormal device activity.
Practical implication: combine MDM enforcement with mobile telemetry that detects overlay abuse, sideloading, and unusual camera or microphone use.
Why ransomware claims and gateway compromise reinforce the same access pattern
Ransomware operators and APT groups are often using different tactics to reach the same outcome: control of trusted systems that sit close to identity and data. The report’s ransomware ecosystem section and the appliance exploitation cases both point to opportunistic pressure on organisations with weak exposure management. Once perimeter control is lost, attackers can modify routes, intercept traffic, or stage internal movement before defenders can re-establish trust.
Practical implication: map externally reachable assets to privilege-bearing paths and rehearse containment steps before a compromise spreads.
Threat narrative
Attacker objective: The objective is to obtain trusted access that enables credential harvesting, perimeter control, and downstream lateral movement inside enterprise environments.
- Entry began with exploitation of exposed network appliance flaws and mobile trojan delivery through legitimate-looking app channels.
- Escalation followed through root or admin access on gateways, forged SSO acceptance, or credential capture from overlay attacks.
- Impact came from email interception, VPN and firewall credential exposure, internal pivoting, and ransomware pressure on weakened environments.
Breaches seen in the wild
- IOS app secrets leakage report — iOS apps leaking hardcoded secrets and credentials endangering user privacy.
- Cisco Active Directory credentials breach — Kraken ransomware group leaked Cisco Active Directory credentials.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Active exploitation is now an identity governance problem, not just a vulnerability problem. The report shows attackers using exposed appliances to intercept or forge access, which means the control failure is often trust in the system boundary itself. When gateways and SSO layers are compromised, IAM assumptions about authenticated sessions become unreliable. Practitioners should manage externally reachable systems as part of identity risk, not as separate infrastructure hygiene.
Perimeter trust collapse: is the right concept for this weekly pattern. Once an email gateway or remote access appliance is compromised, the attacker inherits a trust position that can be used to observe credentials, alter traffic, or impersonate legitimate access. That is especially relevant to NHI and service-to-service traffic where session tokens and API credentials may traverse the same trusted paths. The practical conclusion is that exposure management and privilege governance now overlap at the network edge.
Mobile trojanisation expands the identity attack surface beyond managed workstations. Cellik shows that app-store trust can be abused to steal credentials from BYOD devices, where identity controls are often weaker and device posture is less consistent. This matters because consumer-style mobile compromise can still lead to enterprise session theft, MFA fatigue, or account takeover. Security teams should treat mobile access as a governed identity channel, not a convenience layer.
Darkweb claim volume should be read as an operational pressure signal, not noise. High claim counts and holiday-period staffing reductions create a risk window where defenders are slower to validate, triage, and contain. That does not prove every claim is real, but it does indicate a crowded threat market that increases the odds of successful follow-on intrusion. For practitioners, the implication is to tighten exposure monitoring and incident triage when staffing is reduced.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- From our research: Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, according to The State of Non-Human Identity Security.
- That confidence gap should push teams to pair perimeter exposure monitoring with Ultimate Guide to NHIs , Key Challenges and Risks and formal control mapping.
What this signals
Perimeter compromise and mobile credential theft are converging into the same governance problem. When externally reachable devices and unmanaged phones can both yield sessions, tokens, or admin access, the control boundary shifts from infrastructure ownership to identity assurance. For teams running NHI or human IAM programmes, this is a reminder to align exposure management with access governance, not treat them as separate workstreams.
Standing trust in gateways and app stores is becoming a measurable risk surface. The more privilege a trusted device or distribution channel holds, the more attractive it is to attackers looking for quick conversion from exploit to access. Teams should expect more incidents where the first compromise is not the account itself, but the trust path that leads to it.
The practical response is to tighten review cycles around externally exposed systems and privilege-bearing mobile access. Pair that with guidance such as the The 52 NHI breaches Report to understand how quickly trusted access can become breach material.
For practitioners
- Prioritise internet-facing appliance exposure review Inventory all exposed email gateways, VPN concentrators, and firewall management surfaces, then validate whether patching, feature flags, or quarantine services create unauthenticated or low-friction entry points.
- Enforce mobile application control on BYOD Block sideloaded APKs through MDM, require device compliance for business access, and alert on overlay behaviour, anomalous permission requests, or unusual sensor use.
- Review SSO and federation trust assumptions Check whether forged or replayed authentication assertions could still be accepted on perimeter devices, then tighten certificate validation, logging, and config export protections.
- Correlate perimeter alerts with identity telemetry Join gateway events to IAM, PAM, and MFA logs so that credential harvesting or unexpected admin sessions are visible as one chain instead of isolated alerts.
Key takeaways
- Active exploitation of perimeter devices is an identity problem because compromised gateways can intercept, forge, or redirect trusted access.
- The week’s ransomware and mobile trojan activity shows that attackers are exploiting whichever trust path is fastest, not whichever control team owns it.
- Practitioners should respond by joining exposure management, federation validation, and mobile posture controls into one access-risk workflow.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 Initial Access; TA0006 Credential Access; TA0008 Lateral Movement; TA0040 Impact | The report centres on exploit-to-access chains and downstream movement. |
| NIST CSF 2.0 | PR.AC-4 | The article highlights compromised access paths and trust boundaries. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential and session abuse are central in the report. |
| CIS Controls v8 | CIS-5 , Account Management | The report involves privileged sessions, account misuse, and exposed access paths. |
| NIST Zero Trust (SP 800-207) | The report shows why trusted perimeter paths need continuous verification. |
Map exposed appliances and mobile trojans to ATT&CK tactics and prioritize controls that block initial access and credential abuse.
Key terms
- Perimeter trust: Perimeter trust is the assumption that a successful login at the edge remains valid for broad internal access. In practice, it turns one authentication event into a durable entitlement. That model is fragile because any flaw in the gateway or session token can expose the full network, not just one application.
- Trojanized Application: A trojanized application is a legitimate-looking app that has been altered to carry malicious code. Users believe they are installing a normal tool, but the bundled payload can execute backdoors, steal data, or establish persistence immediately after launch.
- Federation trust abuse: The misuse of SSO or SAML trust relationships to obtain access without a valid human login or legitimate session context. It is especially dangerous when a device or identity provider accepts forged assertions, weak signatures, or exported configuration data.
- Identity-adjacent exposure: Identity-adjacent exposure is vulnerability risk that can affect authentication, authorization, tenant administration, or access governance without being a pure IAM defect. It is a useful lens for Microsoft environments because patching can change who can reach what, not just whether a host is secure.
What's in the full article
FireCompass's full weekly report covers the operational detail this post intentionally leaves for the source:
- Exact attack flow for Cisco AsyncOS RCE, including the quarantine path and backdoor behaviour
- Technical request and response patterns for the Fortinet SSO bypass that exposed admin sessions
- The darkweb claim mix by family, including the 64 tracked claims and ransomware distribution
- CISO takeaways on specific defensive actions for SEG exposure, mobile threat hunting, and perimeter validation
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance and secrets management in the context of access risk and lifecycle control. It is designed for practitioners who need a stronger operating model for identity governance across modern environments.
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org