Analysis of ArcaneDoor Threat Infrastructure Suggests Potential Ties to Chinese-based Actor
ID: 45f65493-aa28-528a-9d04-26de12acde9e
STIX ID: report--45f65493-aa28-528a-9d04-26de12acde9e
Feed Name: Censys Blog
Date Published: 2024-05-01
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
Cisco Talos uncovered three zero-day vulnerabilities in Cisco ASA/FTD (CVE-2024-20353, CVE-2024-20359, CVE-2024-20358) that were used by a state-linked actor tracked as UAT4356 in the ArcaneDoor espionage campaign targeting government perimeter network devices globally since January 2024; Talos observed active exploitation of two of the flaws and published advisories and updates. Independent Censys analysis of Talos-provided IPs and certificate indicators found actor infrastructure spanning multiple providers, a concentration in Chinese networks, and services tied to Chinese-developed anti-censorship projects (e.g., Xray/Trojan panels), strengthening the hypothesis of China-based infrastructure, while Cisco has released patches and integrity-check guidance for affected firewall devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
