LINE RUNNER is a persistent Lua-based webshell and backdoor used by the state-sponsored threat actor UAT4356, also tracked as STORM-1849, in the ArcaneDoor espionage campaign. It targets Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense perimeter devices, particularly their WebVPN customization functionality. The implant establishes persistence by abusing the behavior addressed by CVE-2024-20359, allowing it to survive device reboots and firmware upgrades.
LINE RUNNER intercepts requests to legitimate Cisco WebVPN and AnyConnect endpoints and, when supplied with victim-specific tokenized parameters, executes attacker-provided Lua code without normal authentication. It can support remote command execution, configuration collection and modification, packet-capture collection, retrieval of staged data, and exfiltration over HTTP. It also employs anti-forensic and defense-evasion measures, including suppression of syslog activity, concealment of malicious components from ordinary administrative views, cleanup of artifacts, and modification of system behavior to restore persistence. It has been deployed alongside the memory-resident LINE DANCER shellcode loader. ArcaneDoor activity primarily targeted government, telecommunications, media, critical-infrastructure, and other high-value networks globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-20359 (CVSS: 6.0/10.0 - Medium) is a persistent local code-execution vulnerability. An authenticated local attacker with Administrator-level privileges can copy a crafted file to disk0: and execute arbitrary code with root privileges after the next device reload. | Line Runner is a persistent Lua-based webshell targeting the ASA WebVPN device customisation functionality. It exploits Cisco ASA's SSL VPN session to execute arbitrary shellcode.
CVE-2024-20353 (CVSS: 8.6/10.0 - High) is a denial-of-service vulnerability caused by incomplete error checking when parsing an HTTP header. A crafted HTTP request can cause an affected device to reload unexpectedly. | Line Runner is a persistent Lua-based webshell targeting the ASA WebVPN device customisation functionality. It exploits Cisco ASA's SSL VPN session to execute arbitrary shellcode.
On September 25th, 2025, Cisco disclosed two zero-day vulnerabilities, CVE-2025-20333 (CVSS: 9.9) and CVE-2025-20362 (CVSS: 6.5), in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20333 allows authenticated, remote attackers to execute arbitrary code on vulnerable ASA and FTD instances.
Patches to the three vulnerabilities - CVE-2024-20353 (CVSS 8.6), CVE-2024-20359 (CVSS 6.0) and CVE-2024-20358 (CVSS 6.0) - are included in the advisory... The blogpost from Talos outlines how two of the vulnerabilities were exploited to escalate privileges and to establish persistence.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Line Runner is a persistent Lua-based webshell targeting the ASA WebVPN device customisation functionality. It exploits Cisco ASA's SSL VPN session to execute arbitrary shellcode.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
It modifies the /etc/init.d/unmountfs script to copy the malware ZIP file from a hidden location to disk0 during boot.
‘Line Runner’ and ‘Line Dancer’... were used collectively to conduct malicious actions on-target, which included configuration modification...
UAT4356 deployed two backdoors as components of this campaign, ‘Line Runner’ and ‘Line Dancer,’ which were used collectively to conduct malicious actions on-target.
Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. Dyre has the ability to send information staged on a compromised host externally to C2. Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware previously deployed in the ArcaneDoor campaign against Cisco ASA devices.
Line Runner is a backdoor malware used by threat actors to maintain persistence on compromised Cisco ASA and FTD devices. It allows remote access and control, surviving reboots and software upgrades by modifying device ROMMON.
A persistent webshell/backdoor used in the ArcaneDoor campaign against Cisco ASA devices. It intercepts HTTP requests, checks for victim-dependent 32-character parameters, writes payloads to a Lua script, and executes them, enabling persistence and arbitrary code execution.
Backdoor deployed in the ArcaneDoor campaign to infiltrate Cisco ASA/FTD devices, access network traffic, and execute malicious code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.