Site icon TheCyberThrone

ArcaneDoor Exploits Cisco ASA and FTD

Advertisements

Cisco has warned about a national-state actor who has been actively targeting two previously unknown security vulnerabilities in Cisco products since November to breach government networks.

The campaign, dubbed ArcaneDoor and tracked as UAT4356, was first detected by Cisco when it was contacted by a customer earlier this year. The customer reported suspicious activity on its Cisco Adaptive Security Appliances.

Cisco has yet to identify the initial attack vector employed by the attacks, but during the investigation, it found that the threat actor was exploiting the two so-called zero-day vulnerabilities.

The first vector, designated CVE-2024-20353, is a vulnerability in the management and virtual private network web servers for Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software. It could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service condition.

Advertisements

The second vulnerability, named CVE-2024-20359, allowed for the preloading of virtual private network clients and plug-ins that are available in Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software. It could allow an authenticated, local attacker to execute arbitrary code with root-level privileges.

The attackers were found to be deploying a memory implant called “Line Dancer,” a memory-resident shellcode interpreter that enables adversaries to upload and execute arbitrary shellcode payloads. A shellcode is a small piece of code used to exploit a software vulnerability.

The second implant, a backdoor called “Line Runner,” is also deployed for persistence. It specifically targets the second of the two vulnerabilities, the one relating to a legacy capability in Cisco’s software.

Advertisements

The Line Runner allows attackers to maintain persistence on compromised ASA devices. It exploits a legacy capability related to VPN client pre-loading, triggering at boot by searching for a specific file pattern on disk0:. Upon detection, it unzips and executes a Lua script, providing persistent HTTP-based backdoor access. This backdoor survives reboots and upgrades, allowing threat actors to maintain control. Additionally, the Line Runner was observed retrieving staged information facilitated by the Line Dancer component.

This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor. The researchers added that fixes are available for the zero-days.

Indicators of Compromise

Exit mobile version