UAT4356 is a state-sponsored espionage threat actor tracked by Microsoft as Storm-1849 and associated with the ArcaneDoor activity cluster. The actor has targeted perimeter security appliances, particularly Cisco ASA and Firepower Threat Defense systems, including government and telecommunications environments. Public reporting has linked later activity to a China-affiliated campaign, although Cisco has not publicly assigned UAT4356 to a specific country. The group has exploited zero-day vulnerabilities to obtain elevated execution and establish durable access on network appliances. Its bespoke tooling includes Line Runner and Line Dancer, and later FIRESTARTER and LINE VIPER. These implants and toolkits support remote command execution, packet capture, collection and modification of device configurations, command harvesting, authentication-bypass functionality, and exfiltration through established command-and-control channels. UAT4356 has employed extensive defense evasion and persistence measures, including suppression of logging, tampering with authentication and crash-dump mechanisms, deletion of artifacts, interception of command-line activity, boot-sequence modification, and persistence that can survive normal reboots and firmware updates. The activity demonstrates a focused operational interest in long-term access to edge infrastructure for intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
On September 25, Cisco published two critical advisories regarding CVE-2025-20333 (CVSS 9.9) and CVE-2025-20363 (CVSS 9.0). The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests. The vulnerabilities affect Cisco Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), and IOS. A successful exploitation may lead to complete compromise of the affected device. Active exploitation of these vulnerabilities in targeted attacks has been confirmed.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication.
CVE-2024-20353 (CVSS: 8.6/10.0 - High) is a denial-of-service vulnerability caused by incomplete error checking when parsing an HTTP header. A crafted HTTP request can cause an affected device to reload unexpectedly.
CVE-2024-20359 (CVSS: 6.0/10.0 - Medium) is a persistent local code-execution vulnerability. An authenticated local attacker with Administrator-level privileges can copy a crafted file to disk0: and execute arbitrary code with root privileges after the next device reload.
Patches to the three vulnerabilities - CVE-2024-20353 (CVSS 8.6), CVE-2024-20359 (CVSS 6.0) and CVE-2024-20358 (CVSS 6.0) - are included in the advisory... The blogpost from Talos outlines how two of the vulnerabilities were exploited to escalate privileges and to establish persistence.
2 more CVEs tied to this actor tracked in Mallory.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-affiliated campaign linked to attacks against Cisco firewall and switch infrastructure using remote code execution and privilege escalation to gain persistent unauthorized access.
Associated with exploitation of Cisco ASA/FTD vulnerabilities to deploy the FIRESTARTER backdoor and LINE VIPER post-exploitation toolkit for persistent access to compromised network appliances.
Referenced as an example of a named activity cluster associated with exploiting edge devices to maintain persistent access into targeted networks.
State-sponsored cyber-espionage activity leveraging Cisco zero-day vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.