A state-sponsored espionage campaign dubbed ArcaneDoor targeted internet-facing Cisco ASA and FTD appliances, with activity observed from 2023 and victim compromises identified in early 2024. Cisco, allied cyber agencies, and researchers said the attackers focused on perimeter devices including ASA55xx systems, exploiting flaws in WebVPN and related exposed services to gain remote access and deploy two malware components: Line Runner, a persistent Lua-based webshell, and Line Dancer, a memory-resident shellcode loader. The operation enabled reconnaissance, configuration changes, traffic capture, data exfiltration, and potential lateral movement from trusted network edge infrastructure.
Authorities linked the activity to an advanced threat actor tracked as UAT4356 by Cisco and STORM-1849 by Microsoft, and warned that affected devices included systems running vulnerable firmware such as 9.12 and 9.14. Public guidance highlighted patched vulnerabilities including CVE-2024-20359 and CVE-2024-20353, while the UK NCSC detailed how Line Dancer hijacks WebVPN XML parsing through the <host-scan-reply> field and executes attacker-supplied shellcode entirely in memory. Defenders were urged to patch exposed devices, inspect for indicators of compromise before rebooting because Line Dancer is non-persistent, and use released detection content including behavioral checks, SNORT coverage, and YARA rules.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On 2024-04-24, the UK NCSC issued a Malware Tipper report for Line Dancer. The report documented the implant's in-memory behavior, detection guidance, and a YARA rule to help defenders identify the malware on Cisco ASA devices.
On 2024-04-24, Cisco and allied cyber agencies disclosed active exploitation tied to the ArcaneDoor campaign affecting Cisco ASA and FTD devices. The disclosures identified exploited vulnerabilities, described the espionage-focused activity, and urged defenders to patch and investigate for compromise.
A joint advisory said that since early 2024, a sophisticated state-sponsored actor had been targeting Cisco ASA VPN devices, particularly ASA55xx systems running firmware 9.12 and 9.14. The attackers exploited WebVPN services to gain access and conduct espionage-focused operations.
Cisco observed the first ArcaneDoor activity toward victim Cisco ASA devices in January 2024. The campaign was later assessed as a targeted espionage operation using the Line Runner and Line Dancer backdoors.
Cisco reported observations of infrastructure linked to the ArcaneDoor threat actor in November 2023, with related infrastructure potentially dating back as early as July 2023. This indicates campaign preparation before victim activity was observed.
The UK NCSC reported that Line Dancer was identified being deployed to Cisco ASA devices during cyber-attacks observed in late 2023 and early 2024. The malware is an in-memory shellcode loader later associated with the broader ArcaneDoor activity.
Cisco released patched firmware versions 9.16.4.57, 9.18.4.22, and 9.20.2.10 to address vulnerabilities exploited in the campaign, including CVE-2024-20359 and CVE-2024-20353. Defenders were advised to upgrade, disable WebVPN if patching was not possible, and monitor for indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
mnemonic.io
Open sourcecymulate.com
Open sourcecyber.gc.ca
Open sourceblog.talosintelligence.com
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.