LINE DANCER is a memory-resident shellcode loader used against Cisco Adaptive Security Appliance (ASA) VPN devices in the ArcaneDoor espionage campaign. The campaign has been attributed to the state-sponsored cluster tracked as UAT4356, also known as STORM-1849. LINE DANCER has been observed alongside the persistent LINE RUNNER webshell, but LINE DANCER itself is non-persistent and is removed by reboot.
The implant hijacks processing of a WebVPN host-scan reply field. It validates a victim-specific token, Base64-decodes supplied tasking into shellcode, executes that payload in memory, and returns control to the legitimate parser. This enables operators to run arbitrary shellcode and commands on the compromised appliance.
Observed operations using LINE DANCER included collecting and exfiltrating device configurations, creating and exfiltrating network packet captures, modifying appliance configuration, suppressing system logging, and tampering with crash-dump and AAA-related functionality. These behaviors support espionage, defense evasion, and unauthorized access through bypass of configured authentication controls. ArcaneDoor activity involving LINE DANCER was associated with exploitation of CVE-2024-20353 and CVE-2024-20359 against Cisco ASA and Firepower Threat Defense environments, although the exact initial-access vector was not conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-20359 (CVSS: 6.0/10.0 - Medium) is a persistent local code-execution vulnerability. An authenticated local attacker with Administrator-level privileges can copy a crafted file to disk0: and execute arbitrary code with root privileges after the next device reload. | Line Dancer is an in-memory implant that enables the uploading and execution of arbitrary shellcode payloads. It exploits a legacy VPN client pre-loading mechanism on Cisco ASA devices.
CVE-2024-20353 (CVSS: 8.6/10.0 - High) is a denial-of-service vulnerability caused by incomplete error checking when parsing an HTTP header. A crafted HTTP request can cause an affected device to reload unexpectedly. | Line Dancer is an in-memory implant that enables the uploading and execution of arbitrary shellcode payloads. It exploits a legacy VPN client pre-loading mechanism on Cisco ASA devices.
On September 25th, 2025, Cisco disclosed two zero-day vulnerabilities, CVE-2025-20333 (CVSS: 9.9) and CVE-2025-20362 (CVSS: 6.5), in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20333 allows authenticated, remote attackers to execute arbitrary code on vulnerable ASA and FTD instances.
Patches to the three vulnerabilities - CVE-2024-20353 (CVSS 8.6), CVE-2024-20359 (CVSS 6.0) and CVE-2024-20358 (CVSS 6.0) - are included in the advisory... The blogpost from Talos outlines how two of the vulnerabilities were exploited to escalate privileges and to establish persistence.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Line Dancer is an in-memory implant that enables the uploading and execution of arbitrary shellcode payloads. It exploits a legacy VPN client pre-loading mechanism on Cisco ASA devices.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
It modifies the /etc/init.d/unmountfs script to copy the malware ZIP file from a hidden location to disk0 during boot.
‘Line Runner’ and ‘Line Dancer’... were used collectively to conduct malicious actions on-target, which included configuration modification...
UAT4356 deployed two backdoors as components of this campaign, ‘Line Runner’ and ‘Line Dancer,’ which were used collectively to conduct malicious actions on-target.
...control the enabling and disabling of the devices’ syslog service to obfuscate additional commands...
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The two threats have been used by threat actors to modify configurations, conduct reconnaissance, capture and exfiltrate network traffic, and perform lateral movement to other systems.
Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. Dyre has the ability to send information staged on a compromised host externally to C2. Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.
UAT4356 deployed two backdoors, “Line Runner” and “Line Dancer,” to conduct malicious actions, including configuration modification, reconnaissance, network traffic capture/exfiltration, and potentially lateral movement.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware previously deployed in the ArcaneDoor campaign against Cisco ASA devices.
Referenced as a prior/less comprehensive related malware/tool compared to LINE VIPER; no additional functional details provided in the content.
Line Dancer is an in-memory shellcode loader deployed by threat actors to facilitate the execution of malicious payloads on compromised Cisco ASA and FTD devices. It is used to load and execute shellcode directly in memory, aiding in evasion and persistence.
An in-memory implant/backdoor used in the ArcaneDoor campaign against Cisco ASA/FTD devices. It executes arbitrary shellcode or commands delivered via the host-scan-reply field during SSL VPN session establishment, supporting post-compromise control without persistent disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.