logo

Cisco Zero-Days Anchor 'ArcaneDoor' Cyber-Espionage Campaign

ID: 45d9faab-1c1a-5f42-88dd-3d4d2976116e

STIX ID: report--45d9faab-1c1a-5f42-88dd-3d4d2976116e

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-04-25

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Cisco Talos discovered a state-sponsored campaign dubbed "ArcaneDoor" (UAT4356 / STORM-1849) that used two Cisco ASA zero-day vulnerabilities to deploy two custom backdoors—Line Dancer (memory-resident shellcode executor) and Line Runner (persistence mechanism)—against government networks globally; the report includes evidence of active exploitation, IoCs, detection commands, and remediation steps including patches and removal guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.