Cisco FMC Vulnerability and Blockchain C2
Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.
Based on research by Cisco Talos 2026-09-28 9 steps · 3 queries T1071.001 T1133 T1190
Brief
Why this hunt
Management interfaces for edge security appliances are high-value targets for initial access, and the presence of static credentials and RCE vulnerabilities necessitates a behavioral hunt to confirm if existing instances are compromised. Cisco Talos recently published "We've got one word for it, and it's usually the wrong one" (https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/), describing how adversaries exploit these specific weaknesses in Cisco FMC devices. While a vulnerability scanner tells you a host is susceptible, it cannot tell you if an adversary is already inside. This hunt fills that gap by looking for the behavioral artifacts of a successful breach.
How the hunt flows
The hunt begins by querying the vulnerability inventory for findings related to CVE-2026-20079 and CVE-2026-20316. The hunt identifies every host running the appliance that matches these known vulnerable versions. This step scopes the entire investigation to only those assets that the adversary can actually reach. Next, the hunt performs a parallel audit of network and authentication telemetry. It stack-counts DNS queries to the BNB Smart Chain and specific campaign domains. The hunt filters for lookups occurring on three or fewer hosts. This isolation highlights rare, suspicious traffic that stands out from legitimate, fleet-wide behavior. Simultaneously, the hunt audits successful logons on the scoped Cisco FMC appliances. It looks for unusual source IPs or account names. This identifies potential abuse of static credentials or lateral movement that follows a successful exploit. An analyst or an automated agent then evaluates if the source of a logon matches the host exhibiting the anomalous DNS lookups. Finally, an agent triages the findings by correlating the vulnerability state with the rare DNS lookups and authentication events. The agent provides a per-host verdict of malicious, suspicious, or benign. This correlation is the reason this is a hunt: a simple detection rule for BNB Smart Chain traffic would create too much noise, but focusing on vulnerable management interfaces makes the signal actionable.
What the hunt cannot see
The hunt cannot see activity on appliances that do not report logs to a central repository. If an administrator has not enrolled an appliance in the centralized logging environment, the authentication audit will fail to see the adversary's presence. Additionally, if the adversary uses DNS-over-HTTPS (DoH) to resolve blockchain domains, the DNS activity queries will remain silent.
In this series
Steps
-
Identify vulnerable Cisco FMC appliances
Query · scopingFind appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.
reads hb_vulnerability_findingsqlSELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'What a hit looks like. A list of device UIDs with matching CVEs. Silence suggests no vulnerable appliances were detected by recent scans.
-
Stack-count rare blockchain-related DNS queries
Query · baselineIdentify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.
reads hb_dns_activitysqlSELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASCWhat a hit looks like. DNS lookups for blockchain infrastructure that are unique to a few hosts. Silence means no such lookups occurred.
-
Audit successful FMC logons
Query · triageIdentify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.
reads hb_auth_signinsqlSELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)What a hit looks like. Successful login events on Cisco devices. The analyst or agent will look for unusual source IPs or usernames.
-
Triage vulnerability and activity overlap
Agent triageCorrelate the presence of a vulnerability with rare DNS activity and recent authentication events to determine compromise likelihood.
-
Evaluate compromise confidence
DecisionRoute the hunt based on whether the agent identifies high-confidence indicators of intrusion.
-
Isolate compromised host
Response actionContain the threat by isolating the identified Cisco FMC appliance from the network.
-
Perform forensic investigation
Analyst taskReview the identified activity and confirm whether the logins or DNS queries are truly malicious.
-
Apply patches and close hunt
Analyst taskEnsure all vulnerable devices are remediated and the hunt findings are documented.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| C2 via BNB Smart Chain T1071 |
Yes | rare-blockchain-c2-lookups |
| Cisco FMC vulnerability exploitation T1190 · T1133 |
Yes | identify-vulnerable-appliances, fmc-authentication-audit |
| Social engineering via WebDAV and fake CAPTCHA T1566 |
Out of scope | Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series. |
| Rundll32 ordinal execution T1218.011 |
Out of scope | Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series. |
| EDR termination via BYOVD T1068 · T1562.001 |
Out of scope | Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series. |
| Unauthorized RMM installation T1219 |
Out of scope | Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series. |
| In-memory credential theft T1555 |
Out of scope | Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series. |
Blind spots
- Needs hb_auth_signin or native FMC syslog. If an appliance is not enrolled in the centralized logging environment, the hunt will fail to see the authentication attempt. It would answer whether the static credential was used on a device not reporting to central logs.
- Needs hb_http_activity or network traffic analysis. If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity surface will remain silent. It would answer whether the C2 traffic is hiding inside encrypted DNS queries.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
c2_domains | list[domain] | sec.con, w32.9f1f11a708-100.sbx.tg, w32.c4dd71e347-95.sbx.tg | C2 domains identified in the Talos report. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | List of hostnames identified as vulnerable Cisco FMC instances. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
Source
---
analysis: A simple vulnerability alert does not indicate compromise. This hunt pivots
to authentication logs and stack-counts DNS lookups for unusual infrastructure (BNB
Smart Chain), using an agent to correlate the vulnerability state with behavioral
artifacts that a single detection rule would find too noisy.
blind_spots:
- id: limited-cisco-telemetry
question: whether the static credential was used on a device not reporting to central
logs
requires: hb_auth_signin or native FMC syslog
risk: If an appliance is not enrolled in the centralized logging environment, the
hunt will fail to see the authentication attempt.
stage: initial-access-cisco-fmc-exploitation
- id: dns-over-https
question: whether the C2 traffic is hiding inside encrypted DNS queries
requires: hb_http_activity or network traffic analysis
risk: If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity
surface will remain silent.
stage: c2-blockchain-infrastructure
coverage:
- stage: c2-blockchain-infrastructure
status: covered
steps:
- rare-blockchain-c2-lookups
- stage: initial-access-cisco-fmc-exploitation
status: covered
steps:
- identify-vulnerable-appliances
- fmc-authentication-audit
- reason: Belongs to another part of the "We've got one word for it, and it's usually
the wrong one" series.
stage: initial-access-social-engineering-webdav
status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
the wrong one" series.
stage: execution-rundll32-ordinals
status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
the wrong one" series.
stage: defense-evasion-edr-termination
status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
the wrong one" series.
stage: persistence-netsupport-rmm
status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
the wrong one" series.
stage: credential-access-memory-stealers
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: Edge firewall management interfaces are high-value targets; the presence
of static credentials and RCE vulnerabilities necessitates a behavioral hunt to
confirm if existing instances have already been compromised.
methodology: model-assisted
trigger: intel-report
hypothesis: Adversaries are exploiting unpatched Cisco Firewall Management Center
vulnerabilities to gain initial access and establishing command-and-control communication
via legitimate blockchain infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1133
- attack.t1071.001
name: Cisco FMC Vulnerability and Blockchain C2
parameters:
c2_domains:
default:
- sec.con
- w32.9f1f11a708-100.sbx.tg
- w32.c4dd71e347-95.sbx.tg
description: C2 domains identified in the Talos report.
from:
kind: article
observed: '2026-09-10'
ref: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
type: list[domain]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: List of hostnames identified as vulnerable Cisco FMC instances.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: The hunt begins by identifying devices that already have a known vulnerability.
The analyst should resolve the resulting device UIDs to hostnames and populate the
scope_hosts parameter for subsequent steps to focus the search.
references:
- name: "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong\
\ one"
url: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
related:
- hunt: initial-access-social-engineering-webdav
reason: This hunt focuses on appliance exploitation and network C2, not the WebDAV
social engineering vector.
relation: out-of-scope-alternative
- hunt: uat-10820-stealer-infection-chain
relation: follows
scenario:
stages:
- name: Social engineering via WebDAV and fake CAPTCHA
observables:
- fake CAPTCHA prompts
- WebDAV infection chain
- copying and pasting commands from fake verification prompts
slug: initial-access-social-engineering-webdav
tactic: initial-access
techniques:
- T1566
- name: Rundll32 ordinal execution
observables:
- rundll32.exe
- disguised DLLs
- suspicious ordinal calls
- tmp00055df5.dll
slug: execution-rundll32-ordinals
tactic: defense-evasion
techniques:
- T1218.011
- name: EDR termination via BYOVD
observables:
- vulnerable driver
- terminate EDR software
slug: defense-evasion-edr-termination
tactic: defense-evasion
techniques:
- T1068
- T1562.001
- name: Unauthorized RMM installation
observables:
- NetSupport Manager
- SECOH-QAD.exe
slug: persistence-netsupport-rmm
tactic: persistence
techniques:
- T1219
- name: In-memory credential theft
observables:
- Amatera stealer
- ZigCryptoStealer
slug: credential-access-memory-stealers
tactic: credential-access
techniques:
- T1555
- name: C2 via BNB Smart Chain
observables:
- BNB Smart Chain
- bulletproof hosting
slug: c2-blockchain-infrastructure
tactic: command-and-control
techniques:
- T1071
- name: Cisco FMC vulnerability exploitation
observables:
- CVE-2026-20079
- CVE-2026-20316
- Cisco Secure Firewall Management Center (FMC) Software
- crafted HTTP requests
- static user credentials
slug: initial-access-cisco-fmc-exploitation
tactic: initial-access
techniques:
- T1190
- T1133
summary: Russian threat actor UAT-10820 targets organizations with a WebDAV-based
infection chain that tricks users into executing malicious commands via fake CAPTCHA
prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable
drivers to terminate security software and NetSupport Manager for persistent remote
access.
series:
index: 2
slug: we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one
title: We've got one word for it, and it's usually the wrong one
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
tlp: clear
type: investigation
---
# Cisco FMC Vulnerability and Blockchain C2
This hunt identifies Cisco Secure Firewall Management Center (FMC) appliances vulnerable to CVE-2026-20079 and CVE-2026-20316. It then searches for anomalous successful logons on those devices while simultaneously stack-counting DNS queries to blockchain-related infrastructure and known campaign indicators. An agent evaluates the overlap of vulnerability, rare network activity, and authentication logs to identify active intrusions.
## identify-vulnerable-appliances
<!-- Identify vulnerable Cisco FMC appliances -->
Find appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of device UIDs with matching CVEs. Silence suggests no vulnerable
appliances were detected by recent scans.
reads:
- device_uid
- cve_uid
- severity
- collected_at
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'
```
## investigate-activity
<!-- Investigate corroborating activity -->
parallel:
- → rare-blockchain-c2-lookups
- → fmc-authentication-audit
join: → triage-findings
## rare-blockchain-c2-lookups
<!-- Stack-count rare blockchain-related DNS queries -->
Identify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, c2_domains=c2_domains)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: DNS lookups for blockchain infrastructure that are unique to a few hosts.
Silence means no such lookups occurred.
prevalence:
by: device_hostname
key:
- query_hostname
rare_below: 3
reads:
- query_hostname
- device_hostname
- time
silence: evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC
```
## fmc-authentication-audit
<!-- Audit successful FMC logons -->
Identify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.
```sqlite target=identity role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Successful login events on Cisco devices. The analyst or agent will look
for unusual source IPs or usernames.
reads:
- device_hostname
- actor_user_name
- src_endpoint_ip
- auth_protocol
- time
- metadata_product
- status_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```
## triage-findings
<!-- Triage vulnerability and activity overlap -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-appliances
- rare-blockchain-c2-lookups
- fmc-authentication-audit
max_iterations: 5
objective: Determine if any vulnerable Cisco FMC host exhibits signs of active compromise
based on rare blockchain DNS lookups and authentication activity.
success_criteria: The agent provides a per-host verdict of malicious, suspicious,
or benign.
tools:
- endpoint
- identity
```
## evaluate-compromise
<!-- Evaluate compromise confidence -->
if~: "The triage verdict is malicious for at least one host, indicating a vulnerable device communicating with campaign infrastructure." (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → forensic-investigation
unavailable: → forensic-investigation (blind_spot: limited-cisco-telemetry)
else: → patching-and-closure
## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the Cisco FMC host at the network layer and begin incident response procedures.
```
→ forensic-investigation
## forensic-investigation
<!-- Perform forensic investigation -->
```manual target=analyst
Examine the source IPs from the auth audit and the specific blockchain domains from the DNS query. Confirm with the network team if any legitimate integration uses BNB Smart Chain.
```
→ patching-and-closure
## patching-and-closure
<!-- Apply patches and close hunt -->
```manual target=analyst
Apply the relevant hotfixes for CVE-2026-20079 and CVE-2026-20316. Document any findings of persistence or data theft discovered during the investigation.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.