Cisco Zero-Days Anchor 'ArcaneDoor' Cyber-Espionage Campaign
ID: 45d9faab-1c1a-5f42-88dd-3d4d2976116e
STIX ID: report--45d9faab-1c1a-5f42-88dd-3d4d2976116e
Feed Name: Dark Reading
Date Published: 2024-04-25
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Cisco Talos discovered a state-sponsored campaign dubbed "ArcaneDoor" (UAT4356 / STORM-1849) that used two Cisco ASA zero-day vulnerabilities to deploy two custom backdoors—Line Dancer (memory-resident shellcode executor) and Line Runner (persistence mechanism)—against government networks globally; the report includes evidence of active exploitation, IoCs, detection commands, and remediation steps including patches and removal guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
