Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareLine Dancer | Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms. |
| T1014 Rootkit |
CampaignArcaneDoor | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
| T1027.015 Compression |
MalwareLine Runner | Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359. |
| T1036 Masquerading |
CampaignArcaneDoor | ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances. |
| T1037 Boot or Logon Initialization Scripts |
CampaignArcaneDoor | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
| T1040 Network Sniffing |
CampaignArcaneDoor | ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1040 Network Sniffing |
MalwareLine Dancer | Line Dancer can create and exfiltrate packet captures from compromised environments. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Runner | Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Dancer | Line Dancer exfiltrates collected data via command and control channels. |
| T1055 Process Injection |
CampaignArcaneDoor | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| T1059 Command and Scripting Interpreter |
CampaignArcaneDoor | ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| T1059.008 Network Device CLI |
MalwareLine Dancer | Line Dancer can execute native commands in networking device command line interfaces. |
| T1059.011 Lua |
MalwareLine Runner | Line Runner utilizes Lua scripts for command execution. |
| T1070.004 File Deletion |
CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1070.004 File Deletion |
MalwareLine Runner | Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script. |
| T1071.001 Web Protocols |
CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| T1071.001 Web Protocols |
MalwareLine Runner | Line Runner utilizes an HTTP-based Lua backdoor on victim machines. |
| T1071.001 Web Protocols |
MalwareLine Dancer | Line Dancer uses HTTP POST requests to interact with compromised devices. |
| T1082 System Information Discovery |
MalwareLine Dancer | Line Dancer can gather system configuration information by running the native `show configuration` command. |
| T1102.003 One-Way Communication |
CampaignArcaneDoor | ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| T1556 Modify Authentication Process |
CampaignArcaneDoor | ArcaneDoor included modification of the AAA process to bypass authentication mechanisms. |
| T1557 Adversary-in-the-Middle |
CampaignArcaneDoor | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device. |
| T1557 Adversary-in-the-Middle |
MalwareLine Runner | Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed. |
| T1583.003 Virtual Private Server |
CampaignArcaneDoor | ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control. |
| T1583.006 Web Services |
CampaignArcaneDoor | ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1587.003 Digital Certificates |
CampaignArcaneDoor | ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure. |
| T1653 Power Settings |
MalwareLine Runner | Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload. |
| T1653 Power Settings |
CampaignArcaneDoor | ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant. |
| T1653 Power Settings |
MalwareLine Dancer | Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1690 Prevent Command History Logging |
CampaignArcaneDoor | ArcaneDoor included disabling logging on targeted Cisco ASA appliances. |
| T1690 Prevent Command History Logging |
MalwareLine Dancer | Line Dancer can disable syslog on compromised devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.