Campaign, Jul 2023 to Apr 2024.View on attack.mitre.org
ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
| T1020 Automated Exfiltration |
ArcaneDoor included scripted exfiltration of collected data. |
| T1036 Masquerading |
ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances. |
| T1037 Boot or Logon Initialization Scripts |
ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
| T1040 Network Sniffing |
ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1041 Exfiltration Over C2 Channel |
ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1055 Process Injection |
ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| T1059 Command and Scripting Interpreter |
ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| T1070.004 File Deletion |
ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1071.001 Web Protocols |
ArcaneDoor command and control activity was conducted through HTTP. |
| T1082 System Information Discovery |
ArcaneDoor included collection of victim device configuration information. |
| T1102.003 One-Way Communication |
ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed. |
| T1119 Automated Collection |
ArcaneDoor included collection of packet capture and system configuration information. |
| T1133 External Remote Services |
ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices. |
| T1140 Deobfuscate/Decode Files or Information |
ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.