ATT&CKSoftwareLine Runner

Line Runner

S1188

Malware.View on attack.mitre.org

About this malware

Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts. Line Runner is associated with the ArcaneDoor campaign.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.015
Compression

Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359.

T1041
Exfiltration Over C2 Channel

Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.

T1059.011
Lua

Line Runner utilizes Lua scripts for command execution.

T1070.004
File Deletion

Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script.

T1071.001
Web Protocols

Line Runner utilizes an HTTP-based Lua backdoor on victim machines.

T1505.003
Web Shell

Line Runner is a persistent Lua-based web shell.

T1557
Adversary-in-the-Middle

Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed.

T1653
Power Settings

Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload.

Groups that use it0

None recorded.

Campaigns1

References2

  1. CCCS ArcaneDoor 2024 Open source
    Canadian Centre for Cyber Security. (2024, April 24). Cyber Activity Impacting CISCO ASA VPNs. Retrieved January 6, 2025.
  2. Cisco ArcaneDoor 2024 Open source
    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.