Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Nation-State

ArcaneDoor Espionage Campaign Targeting Cisco Firewalls Linked to China

An analysis of IoCs suggests that a Chinese threat group may be behind the recent ArcaneDoor espionage campaign targeting Cisco firewalls.

The recently uncovered cyberespionage campaign named ArcaneDoor, which involves hacked Cisco firewalls, may be the work of a Chinese threat actor, according to threat hunting and attack surface management firm Censys.

Cisco’s threat intelligence and research unit Talos revealed in late April that it had been investigating an espionage campaign involving exploitation of two zero-day vulnerabilities in its Adaptive Security Appliance (ASA) firewall platform.

The company said a previously unknown group tracked as UAT4356 and Storm-1849 had targeted government networks worldwide in a campaign it tracks as ArcaneDoor. 

The initial attack vector has yet to be identified, but Cisco has determined that the attacks involved exploitation of two zero-day vulnerabilities: CVE-2024-20353, which allows DoS attacks, and CVE-2024-20359, which can be used for persistent local code execution.

The attackers implanted custom malware, executed commands, and attempted to exfiltrate data from compromised devices. 

Advertisement. Scroll to continue reading.

Cisco learned about the attacks in early 2024, but evidence suggests the attackers may have conducted tests as early as July 2023. 

While it shared little attribution information, Talos did say that it’s confident the attacks have been conducted by a state-sponsored threat actor.

When the news broke, Wired said it had learned from sources that the attacks appeared aligned with China’s interests. Research conducted by Censys into the indicators of compromise (IoCs) provided by Talos seems to reinforce the theory.

“When we investigated the actor-controlled IPs provided by Talos in Censys data and cross-referenced the with other certificate indicators, we discovered compelling data suggesting the potential involvement of an actor based in China, including links to multiple major Chinese networks and the presence of Chinese-developed anti-censorship software,” Censys said, pointing out that it’s currently difficult to draw definitive conclusions.

Censys found that four of the five networks hosting systems that present an SSL certificate identified by Talos are based in China.

An investigation of the attacker-controlled IP addresses showed that half of the 22 IPs identified by Talos are still online, indicating ongoing activity. 

Further analysis led Censys researchers to GitHub projects written in Chinese, including anti-censorship tools. 

Related: China-Linked Volt Typhoon Hackers Possibly Targeting Australian, UK Governments

Related: China-Linked ‘Redfly’ Group Targeted Power Grid

Related: Chinese Cyberspies Targeting ASEAN Entities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.