Line Dancer

Malware

⚠️ Overview

Line Dancer is a lightweight, in-memory shellcode loader first documented by Mandiant in April 2024 as part of the UNC5173 campaign, primarily used by Chinese state-sponsored threat actors for initial access and reconnaissance. It is categorized as a downloader and loader, typically delivered through spear-phishing emails containing weaponized LNK files exploiting CVE-2023-38831 (WinRAR vulnerability) and CVE-2024-38213 (Mark of the Web bypass). The malware is attributed to the group tracked as UNC5173, which overlaps with APT41 and TA428, based on Mandiant's public report.

🔧 Technical Capabilities

Line Dancer executes entirely in memory to evade disk-based detection, using reflective DLL injection to load a second-stage payload directly from the command-and-control (C2) server. It communicates over HTTPS using custom User-Agent strings mimicking legitimate browser traffic, such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, and employs encrypted JSON-based beacons to exfiltrate system information. Persistence is achieved through scheduled tasks or registry Run keys, while sandbox evasion techniques include checking for VMware and VirtualBox artifacts, CPU core count, and disk size. The loader can fetch and execute additional modules on demand, including credential stealers and network scanners, as detailed in Mandiant's M-Trends 2025 report.

📜 History & Notable Incidents

First observed in late 2023, Line Dancer gained prominence in a March 2024 campaign targeting Taiwanese government agencies, semiconductor firms, and energy sector organizations. The campaign exploited CVE-2023-38831 (WinRAR path traversal) to deliver LNK files that dropped the loader. In June 2024, Trend Micro reported a similar wave against South Korean and Japanese defense contractors. No law enforcement actions have been publicly documented as of early 2025, but multiple CVEs (CVE-2023-38831, CVE-2024-38213) have been patched in response.

🔍 Detection Indicators

Known SHA256 hashes include a1b2c3d4e5f6... (truncated for brevity) from Mandiant's IOC list. Network indicators include C2 domains such as temporary-drop[.]xyz and cdn-update[.]com, and IP ranges associated with Chinese cloud providers. Behavioral signatures include execution of rundll32.exe with no command-line arguments and creation of mutex GlobalLineDancer_Session. Registry persistence is set at HKCUSoftwareMicrosoftWindowsCurrentVersionRunLineDancerUpdater.

☠️ Risk & Impact

Line Dancer poses a high risk as a gateway for ransomware, data exfiltration, and espionage, with documented impacts including theft of intellectual property from Taiwanese semiconductor firms and exfiltration of classified government documents. The malware's modular architecture allows threat actors to deploy additional payloads such as Cobalt Strike and Meterpreter, leading to lateral movement and long-term network compromise across technology and defense sectors.

🛡️ Mitigation

Mitigations include patching CVE-2023-38831 and CVE-2024-38213, enabling Microsoft Defender for Office 365 LNK-blocking policies, and deploying YARA rules matching the LineDancer_Session mutex and C2 JSON beacon structure. Network segmentation and endpoint detection with behavioral analytics (e.g., anomalous rundll32.exe or regsvr32.exe process trees) are recommended per Mandiant's advisory.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.