China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices
According to recent research from attack surface management company Censys, China-linked attackers may have been responsible for the newly discovered cyber espionage campaign that targeted perimeter network devices from many vendors, including Cisco.
Known as ArcaneDoor, the activity is believed to have started in July 2023, with the first attack against an anonymous target being confirmed in early January 2024.
Two unique malware programs named Line Runner and Line Dancer were used in the targeted attacks, which were led by an as-yet-undocumented, presumed sophisticated state-sponsored actor and tracked as UAT4356 (aka Storm-1849).
Although the initial access method that allowed the intrusions has not yet been identified, the attacker has been seen to continue using Line Runner ...

