ArcaneDoor is a state-sponsored cyberespionage activity cluster associated with the actor tracked by Cisco Talos as UAT4356 and by Microsoft as Storm-1849. ArcaneDoor originally designated the actor's campaign, publicly disclosed in April 2024, and is also used to refer to the broader activity cluster. Its targets include government and telecommunications networks, with a particular focus on perimeter network devices such as firewalls and VPN appliances. Confirmed victims include at least one United States government agency. A specific sponsoring country has not been established at high confidence. The actor demonstrates deep knowledge of network appliance internals and uses bespoke implants to maintain covert access and collect sensitive information. Its 2024 operations exploited CVE-2024-20353 and CVE-2024-20359 in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. The initial access vector for that campaign remained unknown. Its principal implants were Line Runner, a persistent Lua-based web shell, and Line Dancer, an in-memory implant capable of executing arbitrary shellcode and commands. These tools supported device configuration collection and modification, reconnaissance, network traffic capture, remote command execution, and exfiltration over existing command-and-control channels. Defense-evasion techniques include disabling logging, modifying authentication, authorization, and accounting functions, deleting installation artifacts, and tampering with crash diagnostics. Subsequent activity linked to the same actor in 2025 exploited CVE-2025-20333 and CVE-2025-20362 on Cisco ASA and FTD devices. Those intrusions involved malware deployment, interception of command-line operations, deliberate device crashes to obstruct analysis, and, in some cases, modification of the ROM Monitor to preserve access across reboots and software upgrades.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Operators chain CVE-2025-20362 → CVE-2025-20333/20363 for RCE, followed by firmware/ROMMON implant deployment, log tampering, and forced device crashes.
Crafted HTTP(S) requests associated with CVE-2025-20362 expose tokens, cookies, or session metadata; operators replay harvested tokens to obtain an authenticated VPN context and chain into remote code execution.
The executive summary states that only CVE-2024-20353 and CVE-2024-20359 were exploited in the ArcaneDoor campaign, with exploitation going back to January 2024.
The executive summary states that only CVE-2024-20353 and CVE-2024-20359 were exploited in the ArcaneDoor campaign. Cisco has released software updates and provided device-integrity checking steps.
Additional Cisco RCE vulnerability moved from "high risk" to confirmed exploitation status; forensic evidence linked exploitation to advanced firmware implant deployment.
2 more CVEs tied to this actor tracked in Mallory.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-affiliated campaign linked to attacks against Cisco firewall and switch infrastructure using remote code execution and privilege escalation to gain persistent unauthorized access.
Associated with exploitation of Cisco ASA/FTD vulnerabilities to deploy the FIRESTARTER backdoor and LINE VIPER post-exploitation toolkit for persistent access to compromised network appliances.
Referenced as an example of a named activity cluster associated with exploiting edge devices to maintain persistent access into targeted networks.
State-sponsored cyber-espionage activity leveraging Cisco zero-day vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.