How The Activity Unfolds In ATT&CK
ArcaneDoor unfolds at the perimeter: public-facing network devices are compromised, tooling is introduced, traffic is proxied, and cleanup behavior reduces visibility.
- T1190 Exploit Public-Facing Application. The actor reaches exposed perimeter systems.
- T1105 Ingress Tool Transfer. Tools are moved into the compromised environment.
- T1090 Proxy. Compromised infrastructure can become a traffic relay.
- T1070.004 File Deletion. Artifact deletion complicates investigation.
Defender Readout
This is a top activity because it reminds defenders that network devices are production systems with attack paths, persistence risk, and investigation requirements.
Evidence And Mapping Rationale
Exploit Public-Facing Application
MITRE maps ArcaneDoor to exploitation of externally reachable network-device services.
Ingress Tool Transfer
MITRE maps the activity to moving tools into compromised environments.
Proxy
MITRE maps proxy behavior used to route traffic through compromised infrastructure.
File Deletion
MITRE maps file deletion activity used to remove artifacts.