Line Runner

MITRE ATT&CK: S1188 View on attack.mitre.org

Aliases: Line Runner

Malware type
backdoor, webshell
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:13:24

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts. Line Runner is associated with the ArcaneDoor campaign.

Detection coverage

  • 79 Sigma rules

Malware & tools used

  • Exfiltration Over C2 Channel (attack-pattern)
  • Compression (attack-pattern)
  • Power Settings (attack-pattern)
  • Web Protocols (attack-pattern)
  • Lua (attack-pattern)
  • Web Shell (attack-pattern)
  • File Deletion (attack-pattern)
  • Adversary-in-the-Middle (attack-pattern)

Used by threat actors

  • ArcaneDoor (campaign)
  • ArcaneDoor (Deprecated) (campaign)

Reports & references

  • Cisco Talos — Arcanedoor New Espionage Focused Campaign Found Targeting Perimeter Network Devices (report)
  • cyber.gc.ca — Cyber Activity Impacting Cisco Asa Vpns (report)
  • MITRE ATT&CK — S1188 (report)

External references