ATT&CKReferencesCCCS ArcaneDoor 2024

CCCS ArcaneDoor 2024

Canadian Centre for Cyber Security. (2024, April 24). Cyber Activity Impacting CISCO ASA VPNs. Retrieved January 6, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples17

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
CampaignArcaneDoor

ArcaneDoor included scripted exfiltration of collected data.

T1040
Network Sniffing
CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1059.008
Network Device CLI
MalwareLine Dancer

Line Dancer can execute native commands in networking device command line interfaces.

T1059.011
Lua
MalwareLine Runner

Line Runner utilizes Lua scripts for command execution.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1071.001
Web Protocols
MalwareLine Dancer

Line Dancer uses HTTP POST requests to interact with compromised devices.

T1071.001
Web Protocols
MalwareLine Runner

Line Runner utilizes an HTTP-based Lua backdoor on victim machines.

T1082
System Information Discovery
CampaignArcaneDoor

ArcaneDoor included collection of victim device configuration information.

T1119
Automated Collection
CampaignArcaneDoor

ArcaneDoor included collection of packet capture and system configuration information.

T1133
External Remote Services
CampaignArcaneDoor

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

T1140
Deobfuscate/Decode Files or Information
MalwareLine Dancer

Line Dancer shellcode payloads are base64 encoded when transmitted to compromised devices.

T1190
Exploit Public-Facing Application
CampaignArcaneDoor

ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.

T1505.003
Web Shell
MalwareLine Runner

Line Runner is a persistent Lua-based web shell.

T1587.001
Malware
CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

T1685
Disable or Modify Tools
CampaignArcaneDoor

ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.

T1690
Prevent Command History Logging
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.