Storm-1849

Aliases: UAT4356

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:15:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor. They exploited two zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware implants called "Line Runner" and "Line Dancer." The actor demonstrated a deep understanding of Cisco systems, utilized anti-forensic measures, and took deliberate steps to evade detection. UAT4356's sophisticated attack chain allowed them to conduct malicious actions such as configuration modification, reconnaissance, network traffic capture/exfiltration, and potentially lateral movement on compromised devices.

Reports & references

  • Cisco Talos — Arcanedoor New Espionage Focused Campaign Found Targeting Perimeter Network Devices (report)

Attributed from

  • ArcaneDoor (campaign)
  • ArcaneDoor (Deprecated) (campaign)

External references