China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices
ID: ba6901fe-94d7-52c8-ab88-097ae1f596f1
STIX ID: report--ba6901fe-94d7-52c8-ab88-097ae1f596f1
Feed Name: The Hacker News
A newly disclosed espionage campaign dubbed ArcaneDoor, attributed to a suspected China-linked actor (UAT4356/Storm-1849), has been active since mid-2023 and used custom backdoors (Line Runner, Line Dancer) to maintain persistence on perimeter devices; investigators observed exploitation of two now-patched Cisco ASA vulnerabilities (CVE-2024-20353, CVE-2024-20359), links between C2 infrastructure and Chinese autonomous systems, and interest in Microsoft Exchange and other vendor devices. The report also highlights a separate PlugX variant sinkhole revealing global worm-like propagation across millions of IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
