← All hunts high TLP:CLEAR Part 2 of 2

Cisco FMC Vulnerability and Blockchain C2

Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.

Based on research by Cisco Talos 2026-09-28 9 steps · 3 queries T1071.001 T1133 T1190

Brief

Why this hunt

Management interfaces for edge security appliances are high-value targets for initial access, and the presence of static credentials and RCE vulnerabilities necessitates a behavioral hunt to confirm if existing instances are compromised. Cisco Talos recently published "We've got one word for it, and it's usually the wrong one" (https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/), describing how adversaries exploit these specific weaknesses in Cisco FMC devices. While a vulnerability scanner tells you a host is susceptible, it cannot tell you if an adversary is already inside. This hunt fills that gap by looking for the behavioral artifacts of a successful breach.

How the hunt flows

The hunt begins by querying the vulnerability inventory for findings related to CVE-2026-20079 and CVE-2026-20316. The hunt identifies every host running the appliance that matches these known vulnerable versions. This step scopes the entire investigation to only those assets that the adversary can actually reach. Next, the hunt performs a parallel audit of network and authentication telemetry. It stack-counts DNS queries to the BNB Smart Chain and specific campaign domains. The hunt filters for lookups occurring on three or fewer hosts. This isolation highlights rare, suspicious traffic that stands out from legitimate, fleet-wide behavior. Simultaneously, the hunt audits successful logons on the scoped Cisco FMC appliances. It looks for unusual source IPs or account names. This identifies potential abuse of static credentials or lateral movement that follows a successful exploit. An analyst or an automated agent then evaluates if the source of a logon matches the host exhibiting the anomalous DNS lookups. Finally, an agent triages the findings by correlating the vulnerability state with the rare DNS lookups and authentication events. The agent provides a per-host verdict of malicious, suspicious, or benign. This correlation is the reason this is a hunt: a simple detection rule for BNB Smart Chain traffic would create too much noise, but focusing on vulnerable management interfaces makes the signal actionable.

What the hunt cannot see

The hunt cannot see activity on appliances that do not report logs to a central repository. If an administrator has not enrolled an appliance in the centralized logging environment, the authentication audit will fail to see the adversary's presence. Additionally, if the adversary uses DNS-over-HTTPS (DoH) to resolve blockchain domains, the DNS activity queries will remain silent.

In this series

Steps

  1. Identify vulnerable Cisco FMC appliances

    Query · scoping

    Find appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'

    What a hit looks like. A list of device UIDs with matching CVEs. Silence suggests no vulnerable appliances were detected by recent scans.

  2. Stack-count rare blockchain-related DNS queries

    Query · baseline

    Identify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.

    reads hb_dns_activitysql
    SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC

    What a hit looks like. DNS lookups for blockchain infrastructure that are unique to a few hosts. Silence means no such lookups occurred.

  3. Audit successful FMC logons

    Query · triage

    Identify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.

    reads hb_auth_signinsql
    SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. Successful login events on Cisco devices. The analyst or agent will look for unusual source IPs or usernames.

  4. Triage vulnerability and activity overlap

    Agent triage

    Correlate the presence of a vulnerability with rare DNS activity and recent authentication events to determine compromise likelihood.

  5. Evaluate compromise confidence

    Decision

    Route the hunt based on whether the agent identifies high-confidence indicators of intrusion.

  6. Isolate compromised host

    Response action

    Contain the threat by isolating the identified Cisco FMC appliance from the network.

  7. Perform forensic investigation

    Analyst task

    Review the identified activity and confirm whether the logins or DNS queries are truly malicious.

  8. Apply patches and close hunt

    Analyst task

    Ensure all vulnerable devices are remediated and the hunt findings are documented.

Coverage

Scenario coverage

StageCoveredHow, or why not
C2 via BNB Smart Chain
T1071
Yes rare-blockchain-c2-lookups
Cisco FMC vulnerability exploitation
T1190 · T1133
Yes identify-vulnerable-appliances, fmc-authentication-audit
Social engineering via WebDAV and fake CAPTCHA
T1566
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.
Rundll32 ordinal execution
T1218.011
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.
EDR termination via BYOVD
T1068 · T1562.001
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.
Unauthorized RMM installation
T1219
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.
In-memory credential theft
T1555
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.

Blind spots

  • Needs hb_auth_signin or native FMC syslog. If an appliance is not enrolled in the centralized logging environment, the hunt will fail to see the authentication attempt. It would answer whether the static credential was used on a device not reporting to central logs.
  • Needs hb_http_activity or network traffic analysis. If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity surface will remain silent. It would answer whether the C2 traffic is hiding inside encrypted DNS queries.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]sec.con, w32.9f1f11a708-100.sbx.tg, w32.c4dd71e347-95.sbx.tgC2 domains identified in the Talos report.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—List of hostnames identified as vulnerable Cisco FMC instances.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple vulnerability alert does not indicate compromise. This hunt pivots
  to authentication logs and stack-counts DNS lookups for unusual infrastructure (BNB
  Smart Chain), using an agent to correlate the vulnerability state with behavioral
  artifacts that a single detection rule would find too noisy.
blind_spots:
- id: limited-cisco-telemetry
  question: whether the static credential was used on a device not reporting to central
    logs
  requires: hb_auth_signin or native FMC syslog
  risk: If an appliance is not enrolled in the centralized logging environment, the
    hunt will fail to see the authentication attempt.
  stage: initial-access-cisco-fmc-exploitation
- id: dns-over-https
  question: whether the C2 traffic is hiding inside encrypted DNS queries
  requires: hb_http_activity or network traffic analysis
  risk: If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity
    surface will remain silent.
  stage: c2-blockchain-infrastructure
coverage:
- stage: c2-blockchain-infrastructure
  status: covered
  steps:
  - rare-blockchain-c2-lookups
- stage: initial-access-cisco-fmc-exploitation
  status: covered
  steps:
  - identify-vulnerable-appliances
  - fmc-authentication-audit
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: initial-access-social-engineering-webdav
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: execution-rundll32-ordinals
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: defense-evasion-edr-termination
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: persistence-netsupport-rmm
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: credential-access-memory-stealers
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Edge firewall management interfaces are high-value targets; the presence
    of static credentials and RCE vulnerabilities necessitates a behavioral hunt to
    confirm if existing instances have already been compromised.
  methodology: model-assisted
  trigger: intel-report
hypothesis: Adversaries are exploiting unpatched Cisco Firewall Management Center
  vulnerabilities to gain initial access and establishing command-and-control communication
  via legitimate blockchain infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1133
- attack.t1071.001
name: Cisco FMC Vulnerability and Blockchain C2
parameters:
  c2_domains:
    default:
    - sec.con
    - w32.9f1f11a708-100.sbx.tg
    - w32.c4dd71e347-95.sbx.tg
    description: C2 domains identified in the Talos report.
    from:
      kind: article
      observed: '2026-09-10'
      ref: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: List of hostnames identified as vulnerable Cisco FMC instances.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: The hunt begins by identifying devices that already have a known vulnerability.
  The analyst should resolve the resulting device UIDs to hostnames and populate the
  scope_hosts parameter for subsequent steps to focus the search.
references:
- name: "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong\
    \ one"
  url: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
related:
- hunt: initial-access-social-engineering-webdav
  reason: This hunt focuses on appliance exploitation and network C2, not the WebDAV
    social engineering vector.
  relation: out-of-scope-alternative
- hunt: uat-10820-stealer-infection-chain
  relation: follows
scenario:
  stages:
  - name: Social engineering via WebDAV and fake CAPTCHA
    observables:
    - fake CAPTCHA prompts
    - WebDAV infection chain
    - copying and pasting commands from fake verification prompts
    slug: initial-access-social-engineering-webdav
    tactic: initial-access
    techniques:
    - T1566
  - name: Rundll32 ordinal execution
    observables:
    - rundll32.exe
    - disguised DLLs
    - suspicious ordinal calls
    - tmp00055df5.dll
    slug: execution-rundll32-ordinals
    tactic: defense-evasion
    techniques:
    - T1218.011
  - name: EDR termination via BYOVD
    observables:
    - vulnerable driver
    - terminate EDR software
    slug: defense-evasion-edr-termination
    tactic: defense-evasion
    techniques:
    - T1068
    - T1562.001
  - name: Unauthorized RMM installation
    observables:
    - NetSupport Manager
    - SECOH-QAD.exe
    slug: persistence-netsupport-rmm
    tactic: persistence
    techniques:
    - T1219
  - name: In-memory credential theft
    observables:
    - Amatera stealer
    - ZigCryptoStealer
    slug: credential-access-memory-stealers
    tactic: credential-access
    techniques:
    - T1555
  - name: C2 via BNB Smart Chain
    observables:
    - BNB Smart Chain
    - bulletproof hosting
    slug: c2-blockchain-infrastructure
    tactic: command-and-control
    techniques:
    - T1071
  - name: Cisco FMC vulnerability exploitation
    observables:
    - CVE-2026-20079
    - CVE-2026-20316
    - Cisco Secure Firewall Management Center (FMC) Software
    - crafted HTTP requests
    - static user credentials
    slug: initial-access-cisco-fmc-exploitation
    tactic: initial-access
    techniques:
    - T1190
    - T1133
  summary: Russian threat actor UAT-10820 targets organizations with a WebDAV-based
    infection chain that tricks users into executing malicious commands via fake CAPTCHA
    prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable
    drivers to terminate security software and NetSupport Manager for persistent remote
    access.
series:
  index: 2
  slug: we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one
  title: We've got one word for it, and it's usually the wrong one
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# Cisco FMC Vulnerability and Blockchain C2

This hunt identifies Cisco Secure Firewall Management Center (FMC) appliances vulnerable to CVE-2026-20079 and CVE-2026-20316. It then searches for anomalous successful logons on those devices while simultaneously stack-counting DNS queries to blockchain-related infrastructure and known campaign indicators. An agent evaluates the overlap of vulnerability, rare network activity, and authentication logs to identify active intrusions.

## identify-vulnerable-appliances
<!-- Identify vulnerable Cisco FMC appliances -->
Find appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of device UIDs with matching CVEs. Silence suggests no vulnerable
  appliances were detected by recent scans.
reads:
- device_uid
- cve_uid
- severity
- collected_at
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'
```

## investigate-activity
<!-- Investigate corroborating activity -->
parallel:
- → rare-blockchain-c2-lookups
- → fmc-authentication-audit
join: → triage-findings

## rare-blockchain-c2-lookups
<!-- Stack-count rare blockchain-related DNS queries -->
Identify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, c2_domains=c2_domains)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: DNS lookups for blockchain infrastructure that are unique to a few hosts.
  Silence means no such lookups occurred.
prevalence:
  by: device_hostname
  key:
  - query_hostname
  rare_below: 3
reads:
- query_hostname
- device_hostname
- time
silence: evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC
```

## fmc-authentication-audit
<!-- Audit successful FMC logons -->
Identify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.

```sqlite target=identity role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Successful login events on Cisco devices. The analyst or agent will look
  for unusual source IPs or usernames.
reads:
- device_hostname
- actor_user_name
- src_endpoint_ip
- auth_protocol
- time
- metadata_product
- status_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## triage-findings
<!-- Triage vulnerability and activity overlap -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-appliances
- rare-blockchain-c2-lookups
- fmc-authentication-audit
max_iterations: 5
objective: Determine if any vulnerable Cisco FMC host exhibits signs of active compromise
  based on rare blockchain DNS lookups and authentication activity.
success_criteria: The agent provides a per-host verdict of malicious, suspicious,
  or benign.
tools:
- endpoint
- identity
```

## evaluate-compromise
<!-- Evaluate compromise confidence -->
if~: "The triage verdict is malicious for at least one host, indicating a vulnerable device communicating with campaign infrastructure." (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → forensic-investigation
unavailable: → forensic-investigation (blind_spot: limited-cisco-telemetry)
else: → patching-and-closure

## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the Cisco FMC host at the network layer and begin incident response procedures.
```
→ forensic-investigation

## forensic-investigation
<!-- Perform forensic investigation -->
```manual target=analyst
Examine the source IPs from the auth audit and the specific blockchain domains from the DNS query. Confirm with the network team if any legitimate integration uses BNB Smart Chain.
```
→ patching-and-closure

## patching-and-closure
<!-- Apply patches and close hunt -->
```manual target=analyst
Apply the relevant hotfixes for CVE-2026-20079 and CVE-2026-20316. Document any findings of persistence or data theft discovered during the investigation.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.