LINE VIPER is a modular user-mode shellcode loader and post-exploitation implant used against Cisco ASA 5500-X series and related Cisco firewall platforms running ASA software. It has been associated with the threat activity cluster linked by Cisco to ArcaneDoor and, in later reporting, with UAT-4356/Storm-1849. The malware has been observed after initial compromise through Cisco WebVPN-related vulnerabilities including CVE-2025-20333 and CVE-2025-20362, and in some cases is deployed in memory by the RayInitiator GRUB bootkit or later reintroduced through the FIRESTARTER persistence implant.
LINE VIPER is designed for in-memory execution and covert operator access on compromised perimeter devices. It can receive tasking through WebVPN client authentication traffic over HTTPS and has also been reported to support ICMP-based tasking with responses over raw TCP. Its documented capabilities include execution of privileged CLI commands, hidden packet capture, bypass of VPN AAA controls for actor-controlled devices, suppression of selected syslog messages, harvesting of user CLI commands, creation of illegitimate VPN sessions, access to device configuration material including credentials and cryptographic keys, and forced delayed reboot to hinder diagnostics and forensic collection. Reporting also describes anti-forensic behavior tied to rebooting during certain collection actions and reducing observable artifacts.
Operationally, LINE VIPER has been used as a post-exploitation access and control component rather than the long-term persistence layer. In observed intrusions, operators first deployed LINE VIPER to establish covert access and manipulate VPN authentication, then installed FIRESTARTER to preserve access across patching and normal reboots. On devices lacking secure boot, RayInitiator can load LINE VIPER directly into memory and survive firmware upgrades, extending the implant chain. Victimology described in public reporting centers on government and critical network perimeter environments, particularly internet-exposed Cisco security appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On September 25th, 2025, Cisco disclosed two zero-day vulnerabilities, CVE-2025-20333 (CVSS: 9.9) and CVE-2025-20362 (CVSS: 6.5), in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20333 allows authenticated, remote attackers to execute arbitrary code on vulnerable ASA and FTD instances. | This bootkit facilitates the deployment of LINE VIPER, a user-mode shellcode loader, on Cisco ASA 5500-X Series lacking secure boot.
On September 25, Cisco published two critical advisories regarding CVE-2025-20333 (CVSS 9.9) and CVE-2025-20363 (CVSS 9.0). The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests. The vulnerabilities affect Cisco Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), and IOS. A successful exploitation may lead to complete compromise of the affected device. Active exploitation of these vulnerabilities in targeted attacks has been confirmed. | The UK National Cyber Security centre (NCSC-UK) has published a new analysis of the malware components, dubbed RayInitiator and LINE VIPER, to assist with detection and mitigation.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication. | This bootkit facilitates the deployment of LINE VIPER, a user-mode shellcode loader, on Cisco ASA 5500-X Series lacking secure boot.
CISA added that the hackers deployed another strain of malware called Line Viper that established illegitimate virtual private network (VPN) sessions that bypassed all VPN authentication policies.
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This bootkit facilitates the deployment of LINE VIPER, a user-mode shellcode loader, on Cisco ASA 5500-X Series lacking secure boot.
The attack chain begins with exploitation of known vulnerabilities (CVE-2025–20333, CVE-2025–20362) to gain initial access, followed by the deployment of LINE VIPER and FIRESTARTER to take control of the network device itself.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
This activity was associated with user accounts that existed but were no longer active within the agency [T1078].
The attackers successfully exploited these vulnerable devices to deploy malware, execute remote commands, and potentially exfiltrate data.
The hackers ... initially deployed a shellcode loader tracked by the U.K. National Cyber Security Center as Line Viper
The vulnerabilities allow remote attackers to execute arbitrary code as root due to improper validation of user-supplied input in HTTP(S) requests.
This activity was associated with user accounts that existed but were no longer active within the agency [T1078].
CISA identified that APT actors first deployed LINE VIPER to establish illegitimate virtual private network (VPN) sessions [T1133] that bypassed all VPN authentication policies.
CVE-2025–20333 (CVSS 9.9) affects the same WebVPN component and allows an authenticated remote attacker with valid VPN credentials to execute arbitrary code with root privileges.
Cisco's investigation uncovered a sophisticated attack that employed advanced evasion techniques, including disabling logging, intercepting CLI commands, and deliberately crashing devices to thwart diagnostic analysis.
This activity was associated with user accounts that existed but were no longer active within the agency [T1078].
LINE VIPER enabled APT actors access to all configuration elements of the victim Firepower device, including administrative credentials, certificates, and private keys [T1082].
LINE VIPER is loaded into memory by RayInitiator and it receives command and control instructions over WebVPN client authentication sessions over HTTPS or via ICMP with responses over raw TCP.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation toolkit used after initial access on Cisco ASA/FTD devices; described as enabling packet capture, VPN authentication bypass, syslog suppression, and credential harvesting, and as facilitating deployment of FIRESTARTER.
A user-mode shellcode loader used post-exploitation on Cisco devices to provide elevated access and facilitate deployment of FIRESTARTER. It can execute CLI commands, perform packet captures, bypass VPN AAA for actor devices, suppress syslog messages, harvest user CLI commands, and force a delayed reboot.
A post-exploitation implant used by APT actors on compromised Cisco ASA devices. In the described incident, it was deployed before FIRESTARTER and could be delivered/executed via FIRESTARTER’s hook and shellcode mechanism.
A post-exploitation toolkit used on compromised Cisco devices to execute CLI commands, capture packets, bypass VPN AAA for actor devices, suppress syslog messages, harvest user CLI commands, and force delayed reboots. It was deployed via FIRESTARTER-enabled access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.