logo

Analysis of ArcaneDoor Threat Infrastructure Suggests Potential Ties to Chinese-based Actor

ID: 45f65493-aa28-528a-9d04-26de12acde9e

STIX ID: report--45f65493-aa28-528a-9d04-26de12acde9e

Feed Name: Censys Blog

Threat Score
88/100

Date Published: 2024-05-01

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

Cisco Talos uncovered three zero-day vulnerabilities in Cisco ASA/FTD (CVE-2024-20353, CVE-2024-20359, CVE-2024-20358) that were used by a state-linked actor tracked as UAT4356 in the ArcaneDoor espionage campaign targeting government perimeter network devices globally since January 2024; Talos observed active exploitation of two of the flaws and published advisories and updates. Independent Censys analysis of Talos-provided IPs and certificate indicators found actor infrastructure spanning multiple providers, a concentration in Chinese networks, and services tied to Chinese-developed anti-censorship projects (e.g., Xray/Trojan panels), strengthening the hypothesis of China-based infrastructure, while Cisco has released patches and integrity-check guidance for affected firewall devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.