---
analysis: A simple vulnerability alert does not indicate compromise. This hunt pivots
  to authentication logs and stack-counts DNS lookups for unusual infrastructure (BNB
  Smart Chain), using an agent to correlate the vulnerability state with behavioral
  artifacts that a single detection rule would find too noisy.
blind_spots:
- id: limited-cisco-telemetry
  question: whether the static credential was used on a device not reporting to central
    logs
  requires: hb_auth_signin or native FMC syslog
  risk: If an appliance is not enrolled in the centralized logging environment, the
    hunt will fail to see the authentication attempt.
  stage: initial-access-cisco-fmc-exploitation
- id: dns-over-https
  question: whether the C2 traffic is hiding inside encrypted DNS queries
  requires: hb_http_activity or network traffic analysis
  risk: If the malware uses DoH to resolve BNB Smart Chain domains, the hb_dns_activity
    surface will remain silent.
  stage: c2-blockchain-infrastructure
coverage:
- stage: c2-blockchain-infrastructure
  status: covered
  steps:
  - rare-blockchain-c2-lookups
- stage: initial-access-cisco-fmc-exploitation
  status: covered
  steps:
  - identify-vulnerable-appliances
  - fmc-authentication-audit
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: initial-access-social-engineering-webdav
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: execution-rundll32-ordinals
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: defense-evasion-edr-termination
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: persistence-netsupport-rmm
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: credential-access-memory-stealers
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Edge firewall management interfaces are high-value targets; the presence
    of static credentials and RCE vulnerabilities necessitates a behavioral hunt to
    confirm if existing instances have already been compromised.
  methodology: model-assisted
  trigger: intel-report
hypothesis: Adversaries are exploiting unpatched Cisco Firewall Management Center
  vulnerabilities to gain initial access and establishing command-and-control communication
  via legitimate blockchain infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1133
- attack.t1071.001
name: Cisco FMC Vulnerability and Blockchain C2
parameters:
  c2_domains:
    default:
    - sec.con
    - w32.9f1f11a708-100.sbx.tg
    - w32.c4dd71e347-95.sbx.tg
    description: C2 domains identified in the Talos report.
    from:
      kind: article
      observed: '2026-09-10'
      ref: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: List of hostnames identified as vulnerable Cisco FMC instances.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: The hunt begins by identifying devices that already have a known vulnerability.
  The analyst should resolve the resulting device UIDs to hostnames and populate the
  scope_hosts parameter for subsequent steps to focus the search.
references:
- name: "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong\
    \ one"
  url: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
related:
- hunt: initial-access-social-engineering-webdav
  reason: This hunt focuses on appliance exploitation and network C2, not the WebDAV
    social engineering vector.
  relation: out-of-scope-alternative
- hunt: uat-10820-stealer-infection-chain
  relation: follows
scenario:
  stages:
  - name: Social engineering via WebDAV and fake CAPTCHA
    observables:
    - fake CAPTCHA prompts
    - WebDAV infection chain
    - copying and pasting commands from fake verification prompts
    slug: initial-access-social-engineering-webdav
    tactic: initial-access
    techniques:
    - T1566
  - name: Rundll32 ordinal execution
    observables:
    - rundll32.exe
    - disguised DLLs
    - suspicious ordinal calls
    - tmp00055df5.dll
    slug: execution-rundll32-ordinals
    tactic: defense-evasion
    techniques:
    - T1218.011
  - name: EDR termination via BYOVD
    observables:
    - vulnerable driver
    - terminate EDR software
    slug: defense-evasion-edr-termination
    tactic: defense-evasion
    techniques:
    - T1068
    - T1562.001
  - name: Unauthorized RMM installation
    observables:
    - NetSupport Manager
    - SECOH-QAD.exe
    slug: persistence-netsupport-rmm
    tactic: persistence
    techniques:
    - T1219
  - name: In-memory credential theft
    observables:
    - Amatera stealer
    - ZigCryptoStealer
    slug: credential-access-memory-stealers
    tactic: credential-access
    techniques:
    - T1555
  - name: C2 via BNB Smart Chain
    observables:
    - BNB Smart Chain
    - bulletproof hosting
    slug: c2-blockchain-infrastructure
    tactic: command-and-control
    techniques:
    - T1071
  - name: Cisco FMC vulnerability exploitation
    observables:
    - CVE-2026-20079
    - CVE-2026-20316
    - Cisco Secure Firewall Management Center (FMC) Software
    - crafted HTTP requests
    - static user credentials
    slug: initial-access-cisco-fmc-exploitation
    tactic: initial-access
    techniques:
    - T1190
    - T1133
  summary: Russian threat actor UAT-10820 targets organizations with a WebDAV-based
    infection chain that tricks users into executing malicious commands via fake CAPTCHA
    prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable
    drivers to terminate security software and NetSupport Manager for persistent remote
    access.
series:
  index: 2
  slug: we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one
  title: We've got one word for it, and it's usually the wrong one
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# Cisco FMC Vulnerability and Blockchain C2

This hunt identifies Cisco Secure Firewall Management Center (FMC) appliances vulnerable to CVE-2026-20079 and CVE-2026-20316. It then searches for anomalous successful logons on those devices while simultaneously stack-counting DNS queries to blockchain-related infrastructure and known campaign indicators. An agent evaluates the overlap of vulnerability, rare network activity, and authentication logs to identify active intrusions.

## identify-vulnerable-appliances
<!-- Identify vulnerable Cisco FMC appliances -->
Find appliances in the inventory that are susceptible to the disclosed RCE or static credential vulnerabilities.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of device UIDs with matching CVEs. Silence suggests no vulnerable
  appliances were detected by recent scans.
reads:
- device_uid
- cve_uid
- severity
- collected_at
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-20079', 'CVE-2026-20316') AND status != 'suppressed'
```

## investigate-activity
<!-- Investigate corroborating activity -->
parallel:
- → rare-blockchain-c2-lookups
- → fmc-authentication-audit
join: → triage-findings

## rare-blockchain-c2-lookups
<!-- Stack-count rare blockchain-related DNS queries -->
Identify hosts communicating with BNB Smart Chain or known C2 domains by highlighting rare values across the fleet.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, c2_domains=c2_domains)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: DNS lookups for blockchain infrastructure that are unique to a few hosts.
  Silence means no such lookups occurred.
prevalence:
  by: device_hostname
  key:
  - query_hostname
  rare_below: 3
reads:
- query_hostname
- device_hostname
- time
silence: evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(query_hostname) AS domain, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS lookup_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_dns_activity WHERE (LOWER(query_hostname) LIKE '%bnb%' OR instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(query_hostname) HAVING host_count <= 3 ORDER BY host_count ASC
```

## fmc-authentication-audit
<!-- Audit successful FMC logons -->
Identify potential exploitation of static credentials or unauthorized access following an RCE on management interfaces.

```sqlite target=identity role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Successful login events on Cisco devices. The analyst or agent will look
  for unusual source IPs or usernames.
reads:
- device_hostname
- actor_user_name
- src_endpoint_ip
- auth_protocol
- time
- metadata_product
- status_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, src_endpoint_ip, auth_protocol, time FROM hb_auth_signin WHERE metadata_product = 'cisco' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## triage-findings
<!-- Triage vulnerability and activity overlap -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-appliances
- rare-blockchain-c2-lookups
- fmc-authentication-audit
max_iterations: 5
objective: Determine if any vulnerable Cisco FMC host exhibits signs of active compromise
  based on rare blockchain DNS lookups and authentication activity.
success_criteria: The agent provides a per-host verdict of malicious, suspicious,
  or benign.
tools:
- endpoint
- identity
```

## evaluate-compromise
<!-- Evaluate compromise confidence -->
if~: "The triage verdict is malicious for at least one host, indicating a vulnerable device communicating with campaign infrastructure." (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → forensic-investigation
unavailable: → forensic-investigation (blind_spot: limited-cisco-telemetry)
else: → patching-and-closure

## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the Cisco FMC host at the network layer and begin incident response procedures.
```
→ forensic-investigation

## forensic-investigation
<!-- Perform forensic investigation -->
```manual target=analyst
Examine the source IPs from the auth audit and the specific blockchain domains from the DNS query. Confirm with the network team if any legitimate integration uses BNB Smart Chain.
```
→ patching-and-closure

## patching-and-closure
<!-- Apply patches and close hunt -->
```manual target=analyst
Apply the relevant hotfixes for CVE-2026-20079 and CVE-2026-20316. Document any findings of persistence or data theft discovered during the investigation.
```
→ end
