ArcaneDoor last observed
The campaign source marks this as the latest known activity date.
ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.
Each relationship retains its own confidence and source.
Every date says what it measures so catalog dates are not confused with publication dates.
CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.
Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.
No linked CVEs are available.
No linked techniques are available.
No linked malware or tools are available.
No source-linked indicators are available.
Open the original material before making an attribution or response decision.