C0046: ArcaneDoor
ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.[1][2]
Security context for executives and security teams
C0046: ArcaneDoor describes [ArcaneDoor](https://attack.mitre.org/campaigns/C0046) is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. [ArcaneDoor](https://attack.mitre.org/campaigns/C0046) is associated with the deployment of the custom backdoors [Line Runner](https://attack.mitre.org/software/S1188) and [Line Dancer](https://attack.mitre.org/software/S1186). [ArcaneDoor](https://attack.mitre.org/campaigns/C0046) is att...
Executive priority
C0046: ArcaneDoor is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate C0046: ArcaneDoor by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether C0046: ArcaneDoor appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
ArcaneDoor
ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.[1][2]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1102.003 | One-Way CommunicationSub-technique | ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed.[1] |
| Enterprise | T1037 | Boot or Logon Initialization Scripts | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.[1] |
| Enterprise | T1036 | Masquerading | ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.[1] |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control.[1] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | ArcaneDoor included use of existing command and control channels for data exfiltration.[1][2] |
| Enterprise | T1587.003 | Digital CertificatesSub-technique | ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure.[1] |
| Enterprise | T1653 | Power Settings | ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant.[1] |
| Enterprise | T1583.006 | Web ServicesSub-technique | ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.[1] |
| Enterprise | T1020 | Automated Exfiltration | ArcaneDoor included scripted exfiltration of collected data.[2] |
| Enterprise | T1557 | Adversary-in-the-Middle | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.[1] |
| Enterprise | T1587.001 | MalwareSub-technique | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.[2][1] |
| Enterprise | T1119 | Automated Collection | ArcaneDoor included collection of packet capture and system configuration information.[2] |
| Enterprise | T1014 | Rootkit | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.[1] |
| Enterprise | T1556 | Modify Authentication Process | ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.[1] |
| Enterprise | T1040 | Network Sniffing | ArcaneDoor included network packet capture and sniffing for data collection in victim environments.[1][2] |
| Enterprise | T1070.004 | File DeletionSub-technique | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.[1][2] |
| Enterprise | T1059 | Command and Scripting Interpreter | ArcaneDoor included the adversary executing command line interface (CLI) commands.[1] |
| Enterprise | T1690 | Prevent Command History Logging | ArcaneDoor included disabling logging on targeted Cisco ASA appliances.[1][2] |
| Enterprise | T1685 | Disable or Modify Tools | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.[1][2] |
| Enterprise | T1190 | Exploit Public-Facing Application | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.[2] |
| Enterprise | T1082 | System Information Discovery | ArcaneDoor included collection of victim device configuration information.[2] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | ArcaneDoor command and control activity was conducted through HTTP.[1] |
| Enterprise | T1133 | External Remote Services | ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.[2] |
| Enterprise | T1055 | Process Injection | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | ArcaneDoor involved the use of Base64 obfuscated scripts and commands.[1] |
Groups, software, and campaigns
S1186: Line Dancer
Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign. Line Dancer allows an adversary to upload and execute arbitrary shellcode on victim devices.[1][2]
S1188: Line Runner
Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts. Line Runner is associated with the ArcaneDoor campaign.[1][2]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | b2d3013b5072… | ||
| 19.1 | 1.0 | Older bundle | 03554bf3f7c7… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Cisco ArcaneDoor 2024
Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.
Open source URL - [2]CCCS ArcaneDoor 2024
Canadian Centre for Cyber Security. (2024, April 24). Cyber Activity Impacting CISCO ASA VPNs. Retrieved January 6, 2025.
Open source URL - [3]mitre-attackC0046Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
