ArcaneDoor hackers exploit Cisco zero-days to breach govt networks
ID: 085f4235-0377-56ce-a8e2-da99a26dd00c
STIX ID: report--085f4235-0377-56ce-a8e2-da99a26dd00c
Feed Name: Bleeping Computer
Threat Score
Cisco and multiple national cyber agencies warn that a state-backed actor (UAT4356 / STORM-1849) ran the ArcaneDoor campaign exploiting two zero-day flaws in Cisco ASA/FTD firewalls to install two backdoors (Line Runner and Line Dancer). The implants provided persistence, disabled logging, allowed remote execution of Lua code and shellcode, and enabled configuration exfiltration and traffic capture; vendors released patches and issued mitigation and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
