ATT&CKReferencesCisco ArcaneDoor 2024

Cisco ArcaneDoor 2024

Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples35

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareLine Dancer

Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms.

T1014
Rootkit
CampaignArcaneDoor

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

T1027.015
Compression
MalwareLine Runner

Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359.

T1036
Masquerading
CampaignArcaneDoor

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

T1037
Boot or Logon Initialization Scripts
CampaignArcaneDoor

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

T1040
Network Sniffing
CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1040
Network Sniffing
MalwareLine Dancer

Line Dancer can create and exfiltrate packet captures from compromised environments.

T1041
Exfiltration Over C2 Channel
MalwareLine Runner

Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareLine Dancer

Line Dancer exfiltrates collected data via command and control channels.

T1055
Process Injection
CampaignArcaneDoor

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

T1059
Command and Scripting Interpreter
CampaignArcaneDoor

ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1059.008
Network Device CLI
MalwareLine Dancer

Line Dancer can execute native commands in networking device command line interfaces.

T1059.011
Lua
MalwareLine Runner

Line Runner utilizes Lua scripts for command execution.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1070.004
File Deletion
MalwareLine Runner

Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script.

T1071.001
Web Protocols
CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

T1071.001
Web Protocols
MalwareLine Runner

Line Runner utilizes an HTTP-based Lua backdoor on victim machines.

T1071.001
Web Protocols
MalwareLine Dancer

Line Dancer uses HTTP POST requests to interact with compromised devices.

T1082
System Information Discovery
MalwareLine Dancer

Line Dancer can gather system configuration information by running the native `show configuration` command.

T1102.003
One-Way Communication
CampaignArcaneDoor

ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed.

T1140
Deobfuscate/Decode Files or Information
CampaignArcaneDoor

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

T1556
Modify Authentication Process
CampaignArcaneDoor

ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.

T1557
Adversary-in-the-Middle
CampaignArcaneDoor

ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.

T1557
Adversary-in-the-Middle
MalwareLine Runner

Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed.

T1583.003
Virtual Private Server
CampaignArcaneDoor

ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control.

T1583.006
Web Services
CampaignArcaneDoor

ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.

T1587.001
Malware
CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

T1587.003
Digital Certificates
CampaignArcaneDoor

ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure.

T1653
Power Settings
MalwareLine Runner

Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload.

T1653
Power Settings
CampaignArcaneDoor

ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant.

T1653
Power Settings
MalwareLine Dancer

Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes.

T1685
Disable or Modify Tools
CampaignArcaneDoor

ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.

T1690
Prevent Command History Logging
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

T1690
Prevent Command History Logging
MalwareLine Dancer

Line Dancer can disable syslog on compromised devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.