ATT&CKCampaignsArcaneDoor

ArcaneDoor

C0046

Campaign, Jul 2023 to Apr 2024.View on attack.mitre.org

About this campaign

ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1014
Rootkit

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

T1020
Automated Exfiltration

ArcaneDoor included scripted exfiltration of collected data.

T1036
Masquerading

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

T1037
Boot or Logon Initialization Scripts

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

T1040
Network Sniffing

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1041
Exfiltration Over C2 Channel

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1055
Process Injection

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

T1059
Command and Scripting Interpreter

ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1070.004
File Deletion

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1071.001
Web Protocols

ArcaneDoor command and control activity was conducted through HTTP.

T1082
System Information Discovery

ArcaneDoor included collection of victim device configuration information.

T1102.003
One-Way Communication

ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed.

T1119
Automated Collection

ArcaneDoor included collection of packet capture and system configuration information.

T1133
External Remote Services

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

T1140
Deobfuscate/Decode Files or Information

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

View all 25 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software2

References2

  1. CCCS ArcaneDoor 2024 Open source
    Canadian Centre for Cyber Security. (2024, April 24). Cyber Activity Impacting CISCO ASA VPNs. Retrieved January 6, 2025.
  2. Cisco ArcaneDoor 2024 Open source
    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.