ArcaneDoor is a malware family/backdoor referenced in the provided content as being used in attacks against victim environments, including prior campaigns later contrasted with newer activity using the RayInitiator bootkit and the LINE VIPER shellcode loader. The content attributes to ArcaneDoor capabilities including network packet capture and sniffing for data collection, scripted exfiltration of collected data, and multiple instances of file deletion or removal during execution, indicating both collection and anti-forensic behavior. It is also listed in Splunk detection content that maps Cisco Secure Firewall intrusion events and Snort signature IDs to known malware families and threat activity. The provided material does not specify a definitive threat actor attribution, infection vector, or targeted industry for ArcaneDoor beyond its use in victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples include 'Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims,' 'BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file,' and 'Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis.'
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Currently, this detection will alert on the following threat actors or malware families as defined in the cisco_snort_ids_to_threat_mapping lookup: AgentTesla Amadey ArcaneDoor AsyncRAT CastleRAT Chafer DCRAT LokiBot Lumma Stealer Nobelium Quasar Remcos Snake Static Tundra Xworm
ArcaneDoor is a backdoor used in attacks against Cisco ASA firewalls, attributed to a suspected Chinese espionage group.
Named malware/tool referenced in the content without additional description.
Toolset/malware that includes packet capture and network sniffing capabilities for data collection in victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.