Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1849

Also known as: UAT4356, UAT4356 by Talos, CVE-2025-20333, CVE-2025-20362, CVE-2025-20363, STATIC TUNDRA, Sandworm Team, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down

Description

UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor. They exploited two zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware implants called "Line Runner" and "Line Dancer." The actor demonstrated a deep understanding of Cisco systems, utilized anti-forensic measures, and took deliberate steps to evade detection. UAT4356's sophisticated attack chain allowed them to conduct malicious actions such as configuration modification, reconnaissance, network traffic capture/exfiltration, and potentially lateral movement on compromised devices.

Goals & Targeting

Targeted Sectors

Government
Financial services
Energy
Telecommunications
Defense
Healthcare
Critical infrastructure
Education
Manufacturing
Maritime
Aviation
Transportation
Information technology
Media
Hospitality
Non profit
Aerospace
Construction
Retail
Chemical
Think tank
Nuclear
Oil gas
Legal services
Entertainment
Gaming
Food agriculture

Targeted Countries / Regions

CN
UA
US
IN
GB
RU
JP
AU
IR
DE
PL
CA
TW
KR
SG
VN
KP
KZ
IL
TR
FR
BR
MX
ES
IT
PK
BY

AI Analysis

· 1 week ago

Executive Summary

Storm-1849, also known as UAT4356, is a state-sponsored threat actor identified through their involvement in the ArcaneDoor campaign. They exploit zero-day vulnerabilities in Cisco Adaptive Security Appliances to deploy custom malware, demonstrating advanced capabilities and targeting government networks globally.

Goals & Targeting

Storm-1849 likely aims to gather sensitive information for espionage or disrupt operations within targeted governments and technology sectors. Their global reach suggests a broad interest in critical national infrastructure data。

Enhanced Description

Storm-1849 (alias: UAT4356) operates with high technical sophistication, focusing on state-sponsored activities. Their primary attack vector involves exploiting zero-day vulnerabilities in Cisco ASA systems, deploying custom malware named Line Runner and Line Dancer. These tools allow them to perform network reconnaissance, data exfiltration, and lateral movement while evading detection through anti-forensic measures. Targeting critical infrastructure and government sectors globally, their operations highlight a strategic focus on persistent access and intelligence gathering.

Key Capabilities

  • Exploitation of zero-day vulnerabilities
  • Deployment of custom malware (Line Runner, Line Dancer)
  • Anti-forensic tools to avoid detection
  • Network traffic analysis
  • Lateral movement within networks

MITRE ATT&CK Tactics

Persistence
Exfiltration
Clandestine Communication

ATT&CK Techniques

T1539.002
T1569.004

Software / Tooling

Line Runner
Line Dancer

Campaigns & Victims

The ArcaneDoor campaign showcases Storm-1849's ability to launch prolonged and stealthy attacks on government networks, emphasizing their capability for persistent access and data theft. Their use of sophisticated techniques indicates a high level of resource and expertise.

IOC Patterns

  • Network traffic anomalies from Cisco ASA devices
  • Presence of custom malware binaries
  • Scheduled tasks indicative of persistence mechanisms

Recommended Actions

  • Patch and update Cisco ASA systems to mitigate known vulnerabilities
  • Implement network monitoring for unusual traffic patterns
  • Enhance detection capabilities for lateral movement activities
  • Conduct regular security audits focusing on critical infrastructure

Suggested Tags

APT
State-sponsored
Critical Infrastructure Attacks
Government Targeting

Confidence Assessment

The analysis is based on detailed operational data and observed TTPs, providing a high confidence in their APT classification. Gaps include exact targets beyond 'globally' and specific attack timeline details outside 2023.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 1 Email Address 1 Domain 7 MD5 Hash 1 IPv4 Address 10

References

  1. blog.talosintelligence.com — Cited by web research for: UAT4356 by Talos
  2. www.zscaler.com — Cited by web research for: CVE-2025-20333
  3. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  4. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  5. attack.mitre.org — Cited by web research for: T1190

Intel Summary

29

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Zero-Day Exploitation
Backdoor / C2
Government Targeting
State-sponsored
Critical Infrastructure Attacks

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.