logo

ArcaneDoor Unlocked: Tackling State-Sponsored Cyber Espionage in Network Perimeters

ID: 070faef0-4d50-54da-9a5e-8649bbbcaeb0

STIX ID: report--070faef0-4d50-54da-9a5e-8649bbbcaeb0

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2024-04-24

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

**ArcaneDoor espionage campaign:** Cisco has disclosed a sophisticated, state-linked campaign that exploited two zero-day vulnerabilities in Cisco ASA/FTD devices to install Line Runner (persistent boot‑level backdoor) and Line Dancer (in‑memory shellcode execution) malware, enabling traffic interception and persistent access; vendors released patches and detection guidance, and Qualys published QIDs to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.