{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Edge firewall management interfaces are high-value targets; the presence of static credentials and RCE vulnerabilities necessitates a behavioral hunt to confirm if existing instances have already been compromised."
      },
      "name": "Cisco FMC Vulnerability and Blockchain C2",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1133",
        "attack.t1071.001"
      ],
      "series": {
        "slug": "we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one",
        "index": 2,
        "title": "We've got one word for it, and it's usually the wrong one",
        "total": 2
      },
      "related": [
        {
          "hunt": "initial-access-social-engineering-webdav",
          "reason": "This hunt focuses on appliance exploitation and network C2, not the WebDAV social engineering vector.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "uat-10820-stealer-infection-chain",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple vulnerability alert does not indicate compromise. This hunt pivots to authentication logs and stack-counts DNS lookups for unusual infrastructure (BNB Smart Chain), using an agent to correlate the vulnerability state with behavioral artifacts that a single detection rule would find too noisy.",
      "coverage": [
        {
          "stage": "c2-blockchain-infrastructure",
          "steps": [
            "rare-blockchain-c2-lookups"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-cisco-fmc-exploitation",
          "steps": [
            "identify-vulnerable-appliances",
            "fmc-authentication-audit"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-social-engineering-webdav",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-rundll32-ordinals",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-edr-termination",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-netsupport-rmm",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-memory-stealers",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social engineering via WebDAV and fake CAPTCHA",
            "slug": "initial-access-social-engineering-webdav",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "fake CAPTCHA prompts",
              "WebDAV infection chain",
              "copying and pasting commands from fake verification prompts"
            ]
          },
          {
            "name": "Rundll32 ordinal execution",
            "slug": "execution-rundll32-ordinals",
            "tactic": "defense-evasion",
            "techniques": [
              "T1218.011"
            ],
            "observables": [
              "rundll32.exe",
              "disguised DLLs",
              "suspicious ordinal calls",
              "tmp00055df5.dll"
            ]
          },
          {
            "name": "EDR termination via BYOVD",
            "slug": "defense-evasion-edr-termination",
            "tactic": "defense-evasion",
            "techniques": [
              "T1068",
              "T1562.001"
            ],
            "observables": [
              "vulnerable driver",
              "terminate EDR software"
            ]
          },
          {
            "name": "Unauthorized RMM installation",
            "slug": "persistence-netsupport-rmm",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "NetSupport Manager",
              "SECOH-QAD.exe"
            ]
          },
          {
            "name": "In-memory credential theft",
            "slug": "credential-access-memory-stealers",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Amatera stealer",
              "ZigCryptoStealer"
            ]
          },
          {
            "name": "C2 via BNB Smart Chain",
            "slug": "c2-blockchain-infrastructure",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "BNB Smart Chain",
              "bulletproof hosting"
            ]
          },
          {
            "name": "Cisco FMC vulnerability exploitation",
            "slug": "initial-access-cisco-fmc-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1133"
            ],
            "observables": [
              "CVE-2026-20079",
              "CVE-2026-20316",
              "Cisco Secure Firewall Management Center (FMC) Software",
              "crafted HTTP requests",
              "static user credentials"
            ]
          }
        ],
        "summary": "Russian threat actor UAT-10820 targets organizations with a WebDAV-based infection chain that tricks users into executing malicious commands via fake CAPTCHA prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable drivers to terminate security software and NetSupport Manager for persistent remote access."
      },
      "severity": "high",
      "rationale": "The hunt begins by identifying devices that already have a known vulnerability. The analyst should resolve the resulting device UIDs to hostnames and populate the scope_hosts parameter for subsequent steps to focus the search.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/",
            "kind": "article",
            "observed": "2026-09-10"
          },
          "type": "list[domain]",
          "default": [
            "sec.con",
            "w32.9f1f11a708-100.sbx.tg",
            "w32.c4dd71e347-95.sbx.tg"
          ],
          "description": "C2 domains identified in the Talos report."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames identified as vulnerable Cisco FMC instances."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/",
          "name": "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong one"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-cisco-telemetry",
          "risk": "If an appliance is not enrolled in the centralized logging environment, the hunt will fail to see the authentication attempt.",
          "stage": "initial-access-cisco-fmc-exploitation",
          "question": "whether the static credential was used on a device not reporting to central logs",
          "requires": "hb_auth_signin or native FMC syslog"
        },
        {
          "id": "dns-over-https",
          "risk": "If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity surface will remain silent.",
          "stage": "c2-blockchain-infrastructure",
          "question": "whether the C2 traffic is hiding inside encrypted DNS queries",
          "requires": "hb_http_activity or network traffic analysis"
        }
      ]
    },
    "name": "Cisco FMC Vulnerability and Blockchain C2",
    "description": "This hunt identifies Cisco Secure Firewall Management Center (FMC) appliances vulnerable to CVE-2026-20079 and CVE-2026-20316. It then searches for anomalous successful logons on those devices while simultaneously stack-counting DNS queries to blockchain-related infrastructure and known campaign indicators. An agent evaluates the overlap of vulnerability, rare network activity, and authentication logs to identify active intrusions."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one",
          "index": 2,
          "title": "We've got one word for it, and it's usually the wrong one",
          "total": 2
        },
        "coverage": [
          {
            "stage": "c2-blockchain-infrastructure",
            "steps": [
              "rare-blockchain-c2-lookups"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-cisco-fmc-exploitation",
            "steps": [
              "identify-vulnerable-appliances",
              "fmc-authentication-audit"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-social-engineering-webdav",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-rundll32-ordinals",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-edr-termination",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-netsupport-rmm",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-memory-stealers",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "Adversaries are exploiting unpatched Cisco Firewall Management Center vulnerabilities to gain initial access and establishing command-and-control communication via legitimate blockchain infrastructure.",
        "blind_spots": [
          {
            "id": "limited-cisco-telemetry",
            "risk": "If an appliance is not enrolled in the centralized logging environment, the hunt will fail to see the authentication attempt.",
            "stage": "initial-access-cisco-fmc-exploitation",
            "question": "whether the static credential was used on a device not reporting to central logs",
            "requires": "hb_auth_signin or native FMC syslog"
          },
          {
            "id": "dns-over-https",
            "risk": "If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity surface will remain silent.",
            "stage": "c2-blockchain-infrastructure",
            "question": "whether the C2 traffic is hiding inside encrypted DNS queries",
            "requires": "hb_http_activity or network traffic analysis"
          }
        ],
        "scoping_notes": "The hunt begins by identifying devices that already have a known vulnerability. The analyst should resolve the resulting device UIDs to hostnames and populate the scope_hosts parameter for subsequent steps to focus the search.",
        "beyond_detection": "A simple vulnerability alert does not indicate compromise. This hunt pivots to authentication logs and stack-counts DNS lookups for unusual infrastructure (BNB Smart Chain), using an agent to correlate the vulnerability state with behavioral artifacts that a single detection rule would find too noisy."
      }
    },
    {
      "id": "identify-vulnerable-appliances",
      "type": "query",
      "label": "Identify vulnerable Cisco FMC appliances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Find appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.",
        "expected_signal": "A list of device UIDs with matching CVEs. Silence suggests no vulnerable appliances were detected by recent scans."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable Cisco FMC appliances",
        "reads": [
          "device_uid",
          "cve_uid",
          "severity",
          "collected_at",
          "status"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of device UIDs with matching CVEs. Silence suggests no vulnerable appliances were detected by recent scans.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-blockchain-c2-lookups",
      "type": "query",
      "label": "Stack-count rare blockchain-related DNS queries",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_dns_activity",
        "description": "Identify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.",
        "expected_signal": "DNS lookups for blockchain infrastructure that are unique to a few hosts. Silence means no such lookups occurred."
      },
      "parents": [
        {
          "id": "identify-vulnerable-appliances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Stack-count rare blockchain-related DNS queries",
        "reads": [
          "query_hostname",
          "device_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "DNS lookups for blockchain infrastructure that are unique to a few hosts. Silence means no such lookups occurred.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "query_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "fmc-authentication-audit",
      "type": "query",
      "label": "Audit successful FMC logons",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_auth_signin",
        "description": "Identify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.",
        "expected_signal": "Successful login events on Cisco devices. The analyst or agent will look for unusual source IPs or usernames."
      },
      "parents": [
        {
          "id": "identify-vulnerable-appliances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Audit successful FMC logons",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "src_endpoint_ip",
          "auth_protocol",
          "time",
          "metadata_product",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Successful login events on Cisco devices. The analyst or agent will look for unusual source IPs or usernames.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-findings",
      "type": "analytic",
      "label": "Triage vulnerability and activity overlap",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "identify-vulnerable-appliances",
          "rare-blockchain-c2-lookups",
          "fmc-authentication-audit"
        ],
        "objective": "Determine if any vulnerable Cisco FMC host exhibits signs of active compromise based on rare blockchain DNS lookups and authentication activity.",
        "description": "Correlate the presence of a vulnerability with rare DNS activity and recent authentication events to determine compromise likelihood.",
        "max_iterations": 5,
        "expected_signal": "A verdict characterizing the risk per host.",
        "success_criteria": "The agent provides a per-host verdict of malicious, suspicious, or benign."
      },
      "parents": [
        {
          "id": "rare-blockchain-c2-lookups",
          "kind": "merge"
        },
        {
          "id": "fmc-authentication-audit",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evaluate-compromise",
      "type": "checkpoint",
      "label": "Evaluate compromise confidence",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict is malicious for at least one host, indicating a vulnerable device communicating with campaign infrastructure.",
        "condition": "The triage verdict is malicious for at least one host, indicating a vulnerable device communicating with campaign infrastructure.",
        "blind_spot": "limited-cisco-telemetry",
        "confidence": "high",
        "description": "Route the hunt based on whether the agent identifies high-confidence indicators of intrusion.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-findings"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the identified Cisco FMC appliance from the network.",
        "instructions": "Isolate the Cisco FMC host at the network layer and begin incident response procedures.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-investigation",
      "type": "task",
      "label": "Perform forensic investigation",
      "config": {
        "assignee": "analyst",
        "description": "Review the identified activity and confirm whether the logins or DNS queries are truly malicious.",
        "instructions": "Examine the source IPs from the auth audit and the specific blockchain domains from the DNS query. Confirm with the network team if any legitimate integration uses BNB Smart Chain."
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "default"
        },
        {
          "id": "evaluate-compromise",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "patching-and-closure",
      "type": "task",
      "label": "Apply patches and close hunt",
      "config": {
        "assignee": "analyst",
        "description": "Ensure all vulnerable devices are remediated and the hunt findings are documented.",
        "instructions": "Apply the relevant hotfixes for CVE-2026-20079 and CVE-2026-20316. Document any findings of persistence or data theft discovered during the investigation."
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-investigation"
        }
      ]
    }
  ]
}