logo

ArcaneDoor Campaign Targeting Cisco Adaptive Security Appliance 0day (Campaign)

ID: 55d242de-eafb-563e-9b98-3499059ca874

STIX ID: report--55d242de-eafb-563e-9b98-3499059ca874

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2024-04-24

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Cisco disclosed two zero‑day vulnerabilities in ASA/FTD appliances exploited since November 2023 by a state‑linked group (UAT4356/STORM-1849) in the ArcaneDoor espionage campaign. Exploitation allowed denial‑of‑service and persistent local code execution enabling deployment of Line Dancer (in‑memory shellcode loader) and Line Runner (persistent Lua backdoor) to capture and exfiltrate network traffic and maintain covert access; Cisco released security updates and urged immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.