A likely state-sponsored threat actor exploiting Cisco ASA zero-days to deploy custom malware for network espionage.
Analyst brief
Storm-1849 (also tracked as UAT4356) is a likely state-sponsored threat actor that has targeted government networks globally. The actor exploited two zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware implants named "Line Runner" and "Line Dancer." Their key TTPs include configuration modification, reconnaissance, network traffic capture/exfiltration, and potential lateral movement, all while employing anti-forensic measures to evade detection. Defenders should pay close attention to unusual configuration changes on Cisco ASA devices, suspicious traffic flows, and IOCs associated with the "ArcaneDoor" campaign.
Storm-1849
UAT4356
unknown
UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor. They exploited two zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware implants called "Line Runner" and "Line Dancer." The actor demonstrated a deep understanding of Cisco systems, utilized anti-forensic measures, and took deliberate steps to evade detection. UAT4356's sophisticated attack chain allowed them to conduct malicious actions such as configuration modification, reconnaissance, network traffic capture/exfiltration, and potentially lateral movement on compromised devices.