Malware.View on attack.mitre.org
Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign. Line Dancer allows an adversary to upload and execute arbitrary shellcode on victim devices.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms. |
| T1040 Network Sniffing |
Line Dancer can create and exfiltrate packet captures from compromised environments. |
| T1041 Exfiltration Over C2 Channel |
Line Dancer exfiltrates collected data via command and control channels. |
| T1059.008 Network Device CLI |
Line Dancer can execute native commands in networking device command line interfaces. |
| T1071.001 Web Protocols |
Line Dancer uses HTTP POST requests to interact with compromised devices. |
| T1082 System Information Discovery |
Line Dancer can gather system configuration information by running the native `show configuration` command. |
| T1140 Deobfuscate/Decode Files or Information |
Line Dancer shellcode payloads are base64 encoded when transmitted to compromised devices. |
| T1653 Power Settings |
Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes. |
| T1690 Prevent Command History Logging |
Line Dancer can disable syslog on compromised devices. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.