Line Dancer

MITRE ATT&CK: S1186 View on attack.mitre.org

Aliases: Line Dancer

First seen
2021-08-15 00:00:00
Malware type
loader
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:13:26

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign. Line Dancer allows an adversary to upload and execute arbitrary shellcode on victim devices.

Detection coverage

  • 1 YARA rules
  • 90 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Rootkit (attack-pattern)
  • Power Settings (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Network Device CLI (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

  • ArcaneDoor (campaign)
  • ArcaneDoor (Deprecated) (campaign)

Detection rules

  • SIGNATURE_BASE_Line_Dancer (yara-rule)

Reports & references

  • Cisco Talos — Arcanedoor New Espionage Focused Campaign Found Targeting Perimeter Network Devices (report)
  • MITRE ATT&CK — S1186 (report)
  • cyber.gc.ca — Cyber Activity Impacting Cisco Asa Vpns (report)

External references