Line Dancer
MITRE ATT&CK: S1186 View on attack.mitre.org
Aliases: Line Dancer
- First seen
- 2021-08-15 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 13:13:26
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign. Line Dancer allows an adversary to upload and execute arbitrary shellcode on victim devices.
Detection coverage
- 1 YARA rules
- 90 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Prevent Command History Logging (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Web Protocols (attack-pattern)
- Rootkit (attack-pattern)
- Power Settings (attack-pattern)
- Network Sniffing (attack-pattern)
- Network Device CLI (attack-pattern)
- System Information Discovery (attack-pattern)
Used by threat actors
- ArcaneDoor (campaign)
- ArcaneDoor (Deprecated) (campaign)
Detection rules
- SIGNATURE_BASE_Line_Dancer (yara-rule)
Reports & references
- Cisco Talos — Arcanedoor New Espionage Focused Campaign Found Targeting Perimeter Network Devices (report)
- MITRE ATT&CK — S1186 (report)
- cyber.gc.ca — Cyber Activity Impacting Cisco Asa Vpns (report)