Line Runner is a persistent Lua-based webshell targeting Cisco Adaptive Security Appliance (ASA) devices through WebVPN customization and plug-in functionality. It was deployed during the ArcaneDoor espionage campaign disclosed in April 2024, attributed to the state-sponsored threat actor UAT4356, also tracked as STORM-1849. The campaign targeted government and critical national infrastructure networks globally.
Line Runner establishes persistence by abusing CVE-2024-20359, which allows a specially crafted client bundle to execute Lua code during appliance startup. It modifies web content handling and system scripts to install the backdoor and restore its installation bundle during shutdown, enabling persistence across normal reboots and software upgrades. In at least one intrusion, the operators exploited CVE-2024-20353 to force an appliance reboot and trigger installation. The campaign's initial access vector remains unknown.
The webshell executes attacker-supplied Lua scripts delivered through HTTP or HTTPS GET requests to legitimate WebVPN and AnyConnect endpoints. Tasking requires victim-specific tokens and randomized query parameters, restricting access to the implant and hindering broad detection. Line Runner has been deployed alongside Line Dancer, a distinct, memory-resident shellcode loader, and used to retrieve and exfiltrate information staged by that implant over HTTP.
Defense-evasion and anti-forensic mechanisms include hiding malicious customization artifacts from normal administrative views, suppressing evidence of plug-in installation, deleting execution artifacts, manipulating timestamps and ownership, and removing the webshell during customization import or export operations. Its reboot persistence relies on shutdown processing; a hard power-off can interrupt restoration of the installation bundle.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-20359 (CVSS: 6.0/10.0 - Medium) is a persistent local code-execution vulnerability. An authenticated local attacker with Administrator-level privileges can copy a crafted file to disk0: and execute arbitrary code with root privileges after the next device reload. | Line Runner is a persistent Lua-based webshell targeting the ASA WebVPN device customisation functionality. It exploits Cisco ASA's SSL VPN session to execute arbitrary shellcode.
CVE-2024-20353 (CVSS: 8.6/10.0 - High) is a denial-of-service vulnerability caused by incomplete error checking when parsing an HTTP header. A crafted HTTP request can cause an affected device to reload unexpectedly. | Line Runner is a persistent Lua-based webshell targeting the ASA WebVPN device customisation functionality. It exploits Cisco ASA's SSL VPN session to execute arbitrary shellcode.
On September 25th, 2025, Cisco disclosed two zero-day vulnerabilities, CVE-2025-20333 (CVSS: 9.9) and CVE-2025-20362 (CVSS: 6.5), in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20333 allows authenticated, remote attackers to execute arbitrary code on vulnerable ASA and FTD instances.
Patches to the three vulnerabilities - CVE-2024-20353 (CVSS 8.6), CVE-2024-20359 (CVSS 6.0) and CVE-2024-20358 (CVSS 6.0) - are included in the advisory... The blogpost from Talos outlines how two of the vulnerabilities were exploited to escalate privileges and to establish persistence.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco assessed with high confidence that the same operators were responsible for the April 2024 ArcaneDoor campaign, which deployed custom malware frameworks (e.g., Line Dancer and Line Runner) on ASA devices.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. Dyre has the ability to send information staged on a compromised host externally to C2. Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware previously deployed in the ArcaneDoor campaign against Cisco ASA devices.
Custom malware framework deployed on Cisco ASA devices during the April 2024 ArcaneDoor campaign. Mentioned as historical background supporting continuity of actor involvement; the content does not establish its deployment in the current campaign or describe its individual capabilities.
Line Runner is a backdoor malware used by threat actors to maintain persistence on compromised Cisco ASA and FTD devices. It allows remote access and control, surviving reboots and software upgrades by modifying device ROMMON.
A persistent webshell/backdoor used in the ArcaneDoor campaign against Cisco ASA devices. It intercepts HTTP requests, checks for victim-dependent 32-character parameters, writes payloads to a Lua script, and executes them, enabling persistence and arbitrary code execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.