ArcaneDoor
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
ArcaneDoor is a state-sponsored threat actor that first emerged with capability development in July 2023, with infrastructure activity beginning in November 2023 and observed operations in late 2023 and early 2024, followed by renewed activity in 2025 and 2026. This actor, also tracked as UAT4356 by Talos and STORM-1849 by Microsoft, is primarily motivated by espionage. ArcaneDoor distinguishes itself by its proficiency in exploiting zero-day vulnerabilities in critical perimeter network devices, specifically Cisco Adaptive Security Appliances (ASA) and Firepower Threat Defense (FTD), to gain deep, persistent, and stealthy access for intelligence gathering. While not officially attributed by Cisco to a specific nation-state, analysis of their infrastructure suggests potential links to China.
Sectores objetivo (SOCRadar)
Energy & Utilities Public AdministrationTelecommunicationsNational Security&International AffairsExecutive, Legislative, and Other General Government SupportComputer Systems Design and Related Services