Canadian Centre for Cyber Security. (2024, April 24). Cyber Activity Impacting CISCO ASA VPNs. Retrieved January 6, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
CampaignArcaneDoor | ArcaneDoor included scripted exfiltration of collected data. |
| T1040 Network Sniffing |
CampaignArcaneDoor | ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1059.008 Network Device CLI |
MalwareLine Dancer | Line Dancer can execute native commands in networking device command line interfaces. |
| T1059.011 Lua |
MalwareLine Runner | Line Runner utilizes Lua scripts for command execution. |
| T1070.004 File Deletion |
CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1071.001 Web Protocols |
MalwareLine Dancer | Line Dancer uses HTTP POST requests to interact with compromised devices. |
| T1071.001 Web Protocols |
MalwareLine Runner | Line Runner utilizes an HTTP-based Lua backdoor on victim machines. |
| T1082 System Information Discovery |
CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| T1119 Automated Collection |
CampaignArcaneDoor | ArcaneDoor included collection of packet capture and system configuration information. |
| T1133 External Remote Services |
CampaignArcaneDoor | ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLine Dancer | Line Dancer shellcode payloads are base64 encoded when transmitted to compromised devices. |
| T1190 Exploit Public-Facing Application |
CampaignArcaneDoor | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution. |
| T1505.003 Web Shell |
MalwareLine Runner | Line Runner is a persistent Lua-based web shell. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1690 Prevent Command History Logging |
CampaignArcaneDoor | ArcaneDoor included disabling logging on targeted Cisco ASA appliances. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.