Alpha Cyber

Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits

Summary: A targeted campaign dubbed Operation Zero Disco has been observed exploiting a Cisco SNMP vulnerability to gain footholds and deploy rootkits on compromised systems.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Operation Zero Disco Linux rootkit

Summary: A targeted campaign dubbed Operation Zero Disco has been observed exploiting a Cisco SNMP vulnerability to gain footholds and deploy rootkits on compromised systems. This post explains the risk, prioritized mitigations, and concrete detection/remediation steps your organization should take now. If you manage network devices or run SNMP anywhere in your environment, read this and act.

What happened

Attackers leveraged weaknesses in SNMP-enabled Cisco devices to gain unauthorized access, then moved laterally to deliver and install rootkit-capable tooling. The campaign uses off-the-shelf and custom artifacts (archives and tools) to maintain persistence and evade detection. The intent: long-term data access, covert monitoring, or enabling further compromise.

Note: this post focuses on defensive measures. We will not describe exploit code or step‑by‑step attacker techniques.

Why your business should care

SNMP is widely used for network management, many organizations leave SNMP open or configured with weak community strings.
A single compromised network device can provide attackers with rich telemetry and privileged network access.
Rootkits installed on servers or network appliances enable persistent, stealthy data theft and long recovery timelines.

Immediate actions
1. Patch and update
Ensure all Cisco devices (and network infrastructure) are patched to the latest vendor-recommended firmware. Apply Cisco security advisories immediately.

2. Limit SNMP exposure

Disable SNMP where it’s not needed.
For required SNMP: restrict access to specific management IPs, use SNMPv3 with authentication and encryption (avoid v1/v2c).
Apply ACLs to block SNMP from untrusted networks (especially the Internet).

3. Block and remediate identified artifacts (IOCs)
Add the provided SHA256 hashes to your EDR/AV blocklist, quarantine policies, and SIEM detection lists. See the IOC table below.

4. Harden device management
Use out-of-band management or a dedicated management VLAN; enforce MFA for management consoles and change default credentials.

5. Deploy/validate detection tooling
Ensure endpoint detection & response (EDR), network IDS/IPS, and journaling/audit logging are active. Create detections for unusual SNMP traffic, unexpected archive extraction, and new persistent modules (rootkit-like behavior).

6. Incident readiness
If you detect any of the IOCs or suspicious SNMP activity, isolate affected systems, preserve forensic data, and engage an incident response team.

IOC Table, add to blocklists / detection lists

SHA256FilenameRecommended Action
2abc874435c16aa5cfd431b0d9c26095ef4b9429bd82306f054c367e96df49b2UDPcontrol.tarBlock & Quarantine
69d761bdde73ea8e33384cf986d7e9c2d9011f7aad8933e8af64e60a77091e11a2p (arp spoofing tool)Block & Quarantine
B08877f6f1c6c097240a6a8aa4a23243e3b14a1432170bc3fa5fa9886a2b19b4C93K_Toolkit_GD_V1.tarBlock & Quarantine
9b8a896aa2057f46e17b18bbe091d85fb816b1d3232a3178d6aba94df3a92f6aTracelogRStop_RV2_1.tarBlock & Quarantine
81b35152768f28a479ba9f7e27d66042b0d7edcd79355481aa401f3f47a7733bTracelogRStop_RV2_2.tarBlock & Quarantine
3a524bc40ca7c11b68283504f0119caeefd7589edea621d43d5d0cd973354675transport_force_all_1.tarBlock & Quarantine
E303d0c6c59b4dc55edc0212a9319702e9db7fa03185ae9177777b874c02d4c1transport_force_all_2.tarBlock & Quarantine
7cc7aed51adb426e55d82fd74c55b78f6ecbb895a315be721ef149a17f4b3a9btsfz-trans.zipBlock & Quarantine
235dc2d8c92661e5e2797a03bccd2653272ca1ac93401d194d7784930ca17a5atnsz.zipBlock & Quarantine

Add SHA256 values to your EDR/AV signature blocklist and ensure quarantine action.
Configure your SIEM to alert on any file downloads or process creations where file hash matches the above.
If any matches are found, isolate the host immediately and collect memory/disk images for forensic review.

Detection ideas

Monitor for unexpected SNMP sessions from external or unusual internal IPs and alert on SNMPv1/v2c usage.
Alert on creation or extraction of new archive files (.tar, .zip) on critical hosts outside normal change windows.
Watch for suspicious ARP activity or tools associated with ARP spoofing (network anomalies indicating a2p-like behavior).
EDR: alert on processes that inject into kernel or manipulate device drivers, common for rootkit behavior.

How we can help (our services)

At Alpha Cyber, we offer a full lifecycle defensive program tailored to threats like Operation Zero Disco:

  • Vulnerability management & patch orchestration, prioritize and apply vendor fixes to network appliances.
  • Network hardening & SNMP best-practices, design least‑privilege SNMP deployments.Incident Response & Forensics, containment, remediation, and root cause analysis if an infection is found.
  • Penetration Testing & Red Teaming, identify gaps before adversaries exploit them.

Take action now

Don’t wait for an intrusion to find out you were vulnerable. Schedule a vulnerability review or request an urgent SNMP exposure assessment.

Learn more / Book a consultation

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]