logo

ArcaneDoor hackers exploit Cisco zero-days to breach govt networks

ID: 085f4235-0377-56ce-a8e2-da99a26dd00c

STIX ID: report--085f4235-0377-56ce-a8e2-da99a26dd00c

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2024-04-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco and multiple national cyber agencies warn that a state-backed actor (UAT4356 / STORM-1849) ran the ArcaneDoor campaign exploiting two zero-day flaws in Cisco ASA/FTD firewalls to install two backdoors (Line Runner and Line Dancer). The implants provided persistence, disabled logging, allowed remote execution of Lua code and shellcode, and enabled configuration exfiltration and traffic capture; vendors released patches and issued mitigation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.