logo

China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices

ID: ba6901fe-94d7-52c8-ab88-097ae1f596f1

STIX ID: report--ba6901fe-94d7-52c8-ab88-097ae1f596f1

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A newly disclosed espionage campaign dubbed ArcaneDoor, attributed to a suspected China-linked actor (UAT4356/Storm-1849), has been active since mid-2023 and used custom backdoors (Line Runner, Line Dancer) to maintain persistence on perimeter devices; investigators observed exploitation of two now-patched Cisco ASA vulnerabilities (CVE-2024-20353, CVE-2024-20359), links between C2 infrastructure and Chinese autonomous systems, and interest in Microsoft Exchange and other vendor devices. The report also highlights a separate PlugX variant sinkhole revealing global worm-like propagation across millions of IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.