Also known as: UAT4356, UAT4356 by Talos, CVE-2025-20333, CVE-2025-20362, CVE-2025-20363, STATIC TUNDRA, Sandworm Team, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down
UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor. They exploited two zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware implants called "Line Runner" and "Line Dancer." The actor demonstrated a deep understanding of Cisco systems, utilized anti-forensic measures, and took deliberate steps to evade detection. UAT4356's sophisticated attack chain allowed them to conduct malicious actions such as configuration modification, reconnaissance, network traffic capture/exfiltration, and potentially lateral movement on compromised devices.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-1849, also known as UAT4356, is a state-sponsored threat actor identified through their involvement in the ArcaneDoor campaign. They exploit zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware, demonstrating advanced capabilities and targeting government networks globally.
Goals & Targeting
Storm-1849 likely aims to gather sensitive information for espionage or disrupt operations within targeted governments and technology sectors. Their global reach suggests a broad interest in critical national infrastructure data。
Enhanced Description
Storm-1849 (alias: UAT4356) operates with high technical sophistication, focusing on state-sponsored activities. Their primary attack vector involves exploiting zero-day vulnerabilities in Cisco ASA systems, deploying custom malware named Line Runner and Line Dancer. These tools allow them to perform network reconnaissance, data exfiltration, and lateral movement while evading detection through anti-forensic measures. Targeting critical infrastructure and government sectors globally, their operations highlight a strategic focus on persistent access and intelligence gathering.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The ArcaneDoor campaign showcases Storm-1849's ability to launch prolonged and stealthy attacks on government networks, emphasizing their capability for persistent access and data theft. Their use of sophisticated techniques indicates a high level of resource and expertise.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on detailed operational data and observed TTPs, providing a high confidence in their APT classification. Gaps include exact targets beyond 'globally' and specific attack timeline details outside 2023.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics