ArcaneDoor Exploits Cisco ASA and FTD
BARCELONA, SPAIN - JANUARY 30: A logo sits illuminated outside the Cisco booth at ISE 2024 on January 30, 2024 in Barcelona, Spain. This year the 20th edition of Integrated Systems Europe (ISE) is being held, the sixth in Barcelona. The hall occupies the entire surface of the Fira Gran Via exhibition center with 82,000 square meters, 30% more than last year. This year there are 1,340 exhibitors and more than 90,000 visitors are expected to attend. (Photo by Cesc Maymo/Getty Images)

ArcaneDoor Exploits Cisco ASA and FTD


Cisco has warned about a national-state actor who has been actively targeting two previously unknown security vulnerabilities in Cisco products since November to breach government networks.

The campaign, dubbed ArcaneDoor and tracked as UAT4356, was first detected by Cisco when it was contacted by a customer earlier this year. The customer reported suspicious activity on its Cisco Adaptive Security Appliances.

Cisco has yet to identify the initial attack vector employed by the attacks, but during the investigation, it found that the threat actor was exploiting the two so-called zero-day vulnerabilities.

The first vector, designated CVE-2024-20353, is a vulnerability in the management and virtual private network web servers for Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software. It could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service condition.

Advertisements

The second vulnerability, named CVE-2024-20359, allowed for the preloading of virtual private network clients and plug-ins that are available in Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software. It could allow an authenticated, local attacker to execute arbitrary code with root-level privileges.

The attackers were found to be deploying a memory implant called “Line Dancer,” a memory-resident shellcode interpreter that enables adversaries to upload and execute arbitrary shellcode payloads. A shellcode is a small piece of code used to exploit a software vulnerability.

The second implant, a backdoor called “Line Runner,” is also deployed for persistence. It specifically targets the second of the two vulnerabilities, the one relating to a legacy capability in Cisco’s software.

Advertisements

The Line Runner allows attackers to maintain persistence on compromised ASA devices. It exploits a legacy capability related to VPN client pre-loading, triggering at boot by searching for a specific file pattern on disk0:. Upon detection, it unzips and executes a Lua script, providing persistent HTTP-based backdoor access. This backdoor survives reboots and upgrades, allowing threat actors to maintain control. Additionally, the Line Runner was observed retrieving staged information facilitated by the Line Dancer component.

This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor. The researchers added that fixes are available for the zero-days.

Indicators of Compromise

  • 192.36.57.181
  • 185.167.60.85
  • 185.227.111.17
  • 176.31.18.153
  • 172.105.90.154
  • 185.244.210.120
  • 45.86.163.224
  • 172.105.94.93
  • 213.156.138.77
  • 89.44.198.189
  • 45.77.52.253
  • 103.114.200.230
  • 212.193.2.48
  • 51.15.145.37
  • 89.44.198.196
  • 131.196.252.148
  • 213.156.138.78
  • 121.227.168.69
  • 213.156.138.68
  • 194.4.49.6
  • 185.244.210.65
  • 216.238.75.155
  • 5.183.95.95
  • 45.63.119.131
  • 45.76.118.87
  • 45.77.54.14
  • 45.86.163.244
  • 45.128.134.189
  • 89.44.198.16
  • 96.44.159.46
  • 103.20.222.218
  • 103.27.132.69
  • 103.51.140.101
  • 103.119.3.230
  • 103.125.218.198
  • 104.156.232.22
  • 107.148.19.88
  • 107.172.16.208
  • 107.173.140.111
  • 121.37.174.139
  • 139.162.135.12
  • 149.28.166.244
  • 152.70.83.47
  • 154.22.235.13
  • 154.22.235.17
  • 154.39.142.47
  • 172.233.245.241
  • 185.123.101.250
  • 192.210.137.35
  • 194.32.78.183
  • 205.234.232.196
  • 207.148.74.250
  • 216.155.157.136
  • 216.238.66.251
  • 216.238.71.49
  • 216.238.72.201
  • 216.238.74.95
  • 216.238.81.149
  • 216.238.85.220
  • 216.238.86.24

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.