Line Runner
MITRE ATT&CK: S1188 View on attack.mitre.org
Aliases: Line Runner
- Malware type
- backdoor, webshell
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 13:13:24
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:ru country_code:cn
Context
Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts. Line Runner is associated with the ArcaneDoor campaign.
Detection coverage
- 79 Sigma rules
Malware & tools used
- Exfiltration Over C2 Channel (attack-pattern)
- Compression (attack-pattern)
- Power Settings (attack-pattern)
- Web Protocols (attack-pattern)
- Lua (attack-pattern)
- Web Shell (attack-pattern)
- File Deletion (attack-pattern)
- Adversary-in-the-Middle (attack-pattern)
Used by threat actors
- ArcaneDoor (campaign)
- ArcaneDoor (Deprecated) (campaign)
Reports & references
- Cisco Talos — Arcanedoor New Espionage Focused Campaign Found Targeting Perimeter Network Devices (report)
- cyber.gc.ca — Cyber Activity Impacting Cisco Asa Vpns (report)
- MITRE ATT&CK — S1188 (report)