Line Dancer is a memory-resident, 64-bit shellcode loader targeting Cisco Adaptive Security Appliance (ASA) devices. It was observed in attacks during late 2023 and early 2024 associated with the ArcaneDoor espionage campaign, attributed to the state-sponsored threat actor UAT4356, also tracked as Storm-1849. The campaign targeted perimeter network infrastructure, including VPN appliances serving government and critical national infrastructure networks worldwide.
The implant operates within the ASA's LINA process and redirects a function pointer used to parse the WebVPN host-scan-reply XML field. It accepts tasking through HTTP(S) POST requests during SSL VPN session establishment. Requests must contain a victim-specific, hardcoded 32-byte authentication token; matching requests cause the remaining data to be Base64-decoded and executed as shellcode. After execution, control returns to the legitimate parser. The loader resides in a non-file-backed memory region with read, write, and execute permissions and overwrites previously loaded payloads when processing new tasking.
Line Dancer enables arbitrary command execution and additional payload deployment. Its operational capabilities include collecting device configurations, creating and exfiltrating network packet captures, and exfiltrating collected data through command-and-control channels. Associated payloads can disable system logging, interfere with crash-dump collection, and bypass authentication, authorization, and accounting mechanisms to conceal activity and facilitate unauthorized access.
Line Dancer is nonpersistent and distinct from Line Runner, the persistent Lua webshell deployed alongside it. Rebooting removes Line Dancer and its volatile forensic traces; persistence in the paired deployment is provided by Line Runner.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-20359 (CVSS: 6.0/10.0 - Medium) is a persistent local code-execution vulnerability. An authenticated local attacker with Administrator-level privileges can copy a crafted file to disk0: and execute arbitrary code with root privileges after the next device reload. | Line Dancer is an in-memory implant that enables the uploading and execution of arbitrary shellcode payloads. It exploits a legacy VPN client pre-loading mechanism on Cisco ASA devices.
CVE-2024-20353 (CVSS: 8.6/10.0 - High) is a denial-of-service vulnerability caused by incomplete error checking when parsing an HTTP header. A crafted HTTP request can cause an affected device to reload unexpectedly. | Line Dancer is an in-memory implant that enables the uploading and execution of arbitrary shellcode payloads. It exploits a legacy VPN client pre-loading mechanism on Cisco ASA devices.
On September 25th, 2025, Cisco disclosed two zero-day vulnerabilities, CVE-2025-20333 (CVSS: 9.9) and CVE-2025-20362 (CVSS: 6.5), in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20333 allows authenticated, remote attackers to execute arbitrary code on vulnerable ASA and FTD instances.
Patches to the three vulnerabilities - CVE-2024-20353 (CVSS 8.6), CVE-2024-20359 (CVSS 6.0) and CVE-2024-20358 (CVSS 6.0) - are included in the advisory... The blogpost from Talos outlines how two of the vulnerabilities were exploited to escalate privileges and to establish persistence.
The disclosure confirmed that the vulnerabilities are being actively exploited in the wild; CVE-2025-20362 enables remote attackers to access restricted URL endpoints without authentication.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco assessed with high confidence that the same operators were responsible for the April 2024 ArcaneDoor campaign, which deployed custom malware frameworks (e.g., Line Dancer and Line Runner) on ASA devices.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The two threats have been used by threat actors to modify configurations, conduct reconnaissance, capture and exfiltrate network traffic, and perform lateral movement to other systems.
Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. Dyre has the ability to send information staged on a compromised host externally to C2. Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware previously deployed in the ArcaneDoor campaign against Cisco ASA devices.
Custom malware framework deployed on Cisco ASA devices during the April 2024 ArcaneDoor campaign. Mentioned as historical background supporting continuity of actor involvement; the content does not establish its deployment in the current campaign or describe its individual capabilities.
Referenced as a prior/less comprehensive related malware/tool compared to LINE VIPER; no additional functional details provided in the content.
Line Dancer is an in-memory shellcode loader deployed by threat actors to facilitate the execution of malicious payloads on compromised Cisco ASA and FTD devices. It is used to load and execute shellcode directly in memory, aiding in evasion and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.