Uptime Hamster: 10d 18h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ArcaneDoor

ArcaneDoor

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
ArcaneDoor is a state-sponsored threat actor that first emerged with capability development in July 2023, with infrastructure activity beginning in November 2023 and observed operations in late 2023 and early 2024, followed by renewed activity in 2025 and 2026. This actor, also tracked as UAT4356 by Talos and STORM-1849 by Microsoft, is primarily motivated by espionage. ArcaneDoor distinguishes itself by its proficiency in exploiting zero-day vulnerabilities in critical perimeter network devices, specifically Cisco Adaptive Security Appliances (ASA) and Firepower Threat Defense (FTD), to gain deep, persistent, and stealthy access for intelligence gathering. While not officially attributed by Cisco to a specific nation-state, analysis of their infrastructure suggests potential links to China.
Tecnicas MITRE
T1078, T1071.001, T1057, T1047
CVEs relacionadas
CVE-2025-9242, CVE-2025-62221, CVE-2025-62215, CVE-2025-6218, CVE-2025-5777, CVE-2025-55182
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
40
Actualizado
Sat, 27 Ap

Sectores objetivo (SOCRadar)

Energy & Utilities Public AdministrationTelecommunicationsNational Security&International AffairsExecutive, Legislative, and Other General Government SupportComputer Systems Design and Related Services