← All hunts high TLP:CLEAR Part 1 of 2

UAT-10820 Multi-Stage Stealer Infection Chain

An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.

Based on research by Cisco Talos 2026-09-28 12 steps · 5 queries T1068 T1218.011 T1219 T1555 T1562.001 T1566.002

Brief

The Context of UAT-10820 Compromise 13; 13;Cisco

Talos recently detailed a multi-stage infection chain in their article, We've got one word for it, and it's usually the wrong one. The report describes an adversary using deceptive social engineering scripts to mount WebDAV shares, which lead to the deployment of the Amatera stealer and persistent remote access tools. This activity involves specific evasion techniques like rundll32 ordinal loading and the use of vulnerable drivers to disable endpoint security. 13; 13;

How the Hunt Flows

13; 13;The hunt begins by filtering the estate for Windows workstations and servers. This scoping ensures the subsequent queries target systems where WebDAV mounting and DLL loading are viable attack vectors. 13; 13;The first analysis phase runs two queries in parallel to catch the infection at the point of execution. The first search scans script activity logs for command blocks that use net use or dav keywords alongside script execution. This targets the specific behavior of users pasting encoded commands to mount remote attacker-controlled shares. The second query baselines rundll32.exe activity across the environment to find rare command lines using ordinal calls (e.g., ,#1) rather than named function exports. This tactic often disguises the loading of malicious payloads like Amatera. 13; 13;The second phase pivots to persistence and defense evasion markers on any hosts identified in the previous step. The hunt searches for NetSupport Manager (client32.exe) and other RMM tools running from unusual, user-writable directories like AppData or Temp. Simultaneously, it inspects kernel driver activity for the loading of known vulnerable drivers. These drivers, such as those from Process Explorer or IObit, are frequently part of Bring Your Own Vulnerable Driver (BYOVD) attacks aimed at terminating security agents. 13; 13;Finally, an automated agent correlates these findings. It connects the early script execution signals to the rare process commands and the eventual RMM persistence. This links the entire intrusion chain into a single verdict for the analyst. 13; 13;

What the Hunt Cannot See

13; 13;This hunt has two primary blind spots. First, it cannot inspect the contents of encrypted WebDAV traffic. If the initial access does not leave clear script telemetry, the hunt relies entirely on the rundll32 and driver-loading signals. Second, it misses stealers that remain only in memory once the initial loader process terminates. Confirming the presence of memory-resident Amatera components requires live memory forensics or specialized memory scanning. 13; 13;

In this series

Steps

  1. Scope Windows Workstations

    Query · scoping

    Filter the estate to Windows endpoints where WebDAV social engineering and rundll32 ordinal execution are viable.

    reads hb_devicessql
    SELECT DISTINCT hostname AS device_hostname FROM hb_devices WHERE LOWER(platform) = 'windows' AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A list of Windows hostnames. Silence indicates no Windows devices are reporting telemetry.

  2. WebDAV and Interactive Script Leads

    Query · enrichment

    Identify scripts mounting WebDAV shares or running rundll32 from user-pasted commands.

    reads hb_script_activitysql
    SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(script_content) LIKE '%net use%' OR LOWER(script_content) LIKE '%dav%') AND (LOWER(script_content) LIKE '%rundll32%' OR LOWER(script_content) LIKE '%powershell%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Script blocks performing remote mounts or using rundll32. Silence means no such interactive script blocks were logged.

  3. Rundll32 Ordinal Execution Baseline

    Query · baseline

    Identify rare rundll32.exe command lines using ordinal calls instead of function names.

    reads hb_process_activitysql
    SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%rundll32.exe' AND process_cmd_line LIKE '%,#%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts < 5 ORDER BY hosts ASC

    What a hit looks like. Rare command lines where rundll32 executes an export by its ordinal number (e.g., #1).

  4. Early Stage Evidence Review

    Agent triage

    Review script and process results to identify hosts with successful initial infection markers.

  5. Unauthorized RMM Process Activity

    Query · detection candidate

    Identify unauthorized remote access tools running from user-writable directories.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\users\public\%') AND (instr(',' || '{{rmm_filenames}}' || ',', ',' || process_name || ',') > 0 OR LOWER(process_name) LIKE '%netsupport%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Processes associated with RMM tools running from non-standard, user-writable locations. None means no such processes were active.

  6. Vulnerable Driver Loads (BYOVD)

    Query · enrichment

    Identify loads of known vulnerable drivers used to bypass endpoint security.

    reads hb_kernel_extension_activitysql
    SELECT device_hostname, driver_path, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{vulnerable_drivers}}' || ',', ',' || LOWER(driver_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Loads of drivers like procexp.sys or iobitvdrv.sys that are commonly abused for EDR termination.

  7. Full Intrusion Chain Analysis

    Agent triage

    Correlate early stage results with follow-on persistence to confirm a full intrusion chain.

  8. Route on Verdict

    Decision

    Initiate response for confirmed intrusions.

  9. Isolate Endpoint

    Response action

    Halt the compromise and prevent lateral movement or credential exfiltration.

  10. Analyst Forensic Review

    Analyst task

    Verify the agent's findings and assess the impact on credential security.

  11. Hunt Closeout

    Analyst task

    Document findings and tune the baseline if necessary.

Coverage

Scenario coverage

StageCoveredHow, or why not
Social engineering via WebDAV and fake CAPTCHA
T1566
Yes webdav-script-leads
Rundll32 ordinal execution
T1218.011
Yes rundll32-ordinal-prevalence
EDR termination via BYOVD
T1068 · T1562.001
Yes vulnerable-driver-hunt
Unauthorized RMM installation
T1219
Yes rmm-persistence-hunt
In-memory credential theft
T1555
Not visible Memory-resident stealers require memory forensics or specialized memory scanning not provided by standard process snapshots.
C2 via BNB Smart Chain
T1071
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.
Cisco FMC vulnerability exploitation
T1190 · T1133
Out of scope Belongs to another part of the "We've got one word for it, and it's usually the wrong one" series.

Blind spots

  • Needs Endpoint memory scanning or live forensic dump. Since these stealers are often memory-only after injection, standard process snapshots will miss them once the loading process (rundll32) exits. It would answer Are Amatera or ZigCryptoStealer active in memory?.
  • Needs TLS-decrypted HTTP/WebDAV logs. Encrypted WebDAV traffic prevents seeing the specific payload paths, making the hunt reliant on script-pasting behavior. It would answer What were the specific filenames accessed on the WebDAV share?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
rmm_filenameslist[string]SECOH-QAD.exe, client32.exeKnown filenames associated with NetSupport Manager and ProcPatcher.
scope_hostslist[host]—Limit the hunt to specific hosts; leave empty to scan the entire Windows estate.
vulnerable_driverslist[string]procexp.sys, iobitvdrv.sysCommon vulnerable drivers used in BYOVD attacks to terminate EDR.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule might alert on a rundll32 ordinal, but this hunt connects
  that lead to earlier social engineering scripts and follow-on persistence from RMM
  tools, providing the context an analyst needs for a confirmed intrusion verdict.
blind_spots:
- id: memory-only-stealers
  question: Are Amatera or ZigCryptoStealer active in memory?
  requires: Endpoint memory scanning or live forensic dump
  risk: Since these stealers are often memory-only after injection, standard process
    snapshots will miss them once the loading process (rundll32) exits.
  stage: credential-access-memory-stealers
- id: webdav-uri-encryption
  question: What were the specific filenames accessed on the WebDAV share?
  requires: TLS-decrypted HTTP/WebDAV logs
  risk: Encrypted WebDAV traffic prevents seeing the specific payload paths, making
    the hunt reliant on script-pasting behavior.
  stage: initial-access-social-engineering-webdav
coverage:
- stage: initial-access-social-engineering-webdav
  status: covered
  steps:
  - webdav-script-leads
- stage: execution-rundll32-ordinals
  status: covered
  steps:
  - rundll32-ordinal-prevalence
- stage: defense-evasion-edr-termination
  status: covered
  steps:
  - vulnerable-driver-hunt
- stage: persistence-netsupport-rmm
  status: covered
  steps:
  - rmm-persistence-hunt
- blind_spot: memory-only-stealers
  reason: Memory-resident stealers require memory forensics or specialized memory
    scanning not provided by standard process snapshots.
  stage: credential-access-memory-stealers
  status: not_visible
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: c2-blockchain-infrastructure
  status: out_of_scope
- reason: Belongs to another part of the "We've got one word for it, and it's usually
    the wrong one" series.
  stage: initial-access-cisco-fmc-exploitation
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: UAT-10820 uses sophisticated evasion like rundll32 ordinals and BYOVD
    to bypass standard detection. A phased hunt is required to correlate early access
    leads with persistent behavioral indicators.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has infected an endpoint using a WebDAV social engineering
  chain, followed by the execution of disguised DLLs via rundll32 ordinals and the
  installation of unauthorized RMM tools for persistence.
labels:
- hunt
- attack.t1566.002
- attack.t1218.011
- attack.t1219
- attack.t1068
- attack.t1562.001
- attack.t1555
name: UAT-10820 Multi-Stage Stealer Infection Chain
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  rmm_filenames:
    default:
    - SECOH-QAD.exe
    - client32.exe
    description: Known filenames associated with NetSupport Manager and ProcPatcher.
    from:
      kind: article
      observed: '2026-09-10'
      ref: "Talos \u2014 We've got one word for it"
    type: list[string]
  scope_hosts:
    default: []
    description: Limit the hunt to specific hosts; leave empty to scan the entire
      Windows estate.
    type: list[host]
  vulnerable_drivers:
    default:
    - procexp.sys
    - iobitvdrv.sys
    description: Common vulnerable drivers used in BYOVD attacks to terminate EDR.
    from:
      kind: manual
      observed: '2024-01-01'
      ref: Known BYOVD Driver Lists
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on Windows workstations and servers. The hunt assumes EDR telemetry
  for script execution and process activity is enabled.
references:
- name: "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong\
    \ one"
  url: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
related:
- hunt: uat-10820-c2-blockchain-infrastructure
  reason: This hunt focuses on host-based infection markers; C2 activity via BNB Smart
    Chain and Google Visualization requires network-level analysis.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Social engineering via WebDAV and fake CAPTCHA
    observables:
    - fake CAPTCHA prompts
    - WebDAV infection chain
    - copying and pasting commands from fake verification prompts
    slug: initial-access-social-engineering-webdav
    tactic: initial-access
    techniques:
    - T1566
  - name: Rundll32 ordinal execution
    observables:
    - rundll32.exe
    - disguised DLLs
    - suspicious ordinal calls
    - tmp00055df5.dll
    slug: execution-rundll32-ordinals
    tactic: defense-evasion
    techniques:
    - T1218.011
  - name: EDR termination via BYOVD
    observables:
    - vulnerable driver
    - terminate EDR software
    slug: defense-evasion-edr-termination
    tactic: defense-evasion
    techniques:
    - T1068
    - T1562.001
  - name: Unauthorized RMM installation
    observables:
    - NetSupport Manager
    - SECOH-QAD.exe
    slug: persistence-netsupport-rmm
    tactic: persistence
    techniques:
    - T1219
  - name: In-memory credential theft
    observables:
    - Amatera stealer
    - ZigCryptoStealer
    slug: credential-access-memory-stealers
    tactic: credential-access
    techniques:
    - T1555
  - name: C2 via BNB Smart Chain
    observables:
    - BNB Smart Chain
    - bulletproof hosting
    slug: c2-blockchain-infrastructure
    tactic: command-and-control
    techniques:
    - T1071
  - name: Cisco FMC vulnerability exploitation
    observables:
    - CVE-2026-20079
    - CVE-2026-20316
    - Cisco Secure Firewall Management Center (FMC) Software
    - crafted HTTP requests
    - static user credentials
    slug: initial-access-cisco-fmc-exploitation
    tactic: initial-access
    techniques:
    - T1190
    - T1133
  summary: Russian threat actor UAT-10820 targets organizations with a WebDAV-based
    infection chain that tricks users into executing malicious commands via fake CAPTCHA
    prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable
    drivers to terminate security software and NetSupport Manager for persistent remote
    access.
series:
  index: 1
  slug: we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one
  title: We've got one word for it, and it's usually the wrong one
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# UAT-10820 Multi-Stage Stealer Infection Chain

This hunt identifies the multi-stage infection pattern of UAT-10820, starting with interactive scripts that mount WebDAV shares or paste base64-encoded commands. It pivots to identify rare rundll32.exe executions using ordinal calls instead of named exports, a tactic used to load the Amatera stealer. The second phase corroborates these leads by hunting for unauthorized NetSupport Manager installations in user-writable paths and the presence of vulnerable drivers used for EDR termination. The phased agent-led analysis connects early-stage access signals to persistent, high-impact indicators.

## scope-windows-endpoints
<!-- Scope Windows Workstations -->
Filter the estate to Windows endpoints where WebDAV social engineering and rundll32 ordinal execution are viable.

```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days)
~~~yaml
expected: A list of Windows hostnames. Silence indicates no Windows devices are reporting
  telemetry.
reads:
- hostname
- platform
- time
silence: not_evidence_of_absence
source: hb_devices
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT DISTINCT hostname AS device_hostname FROM hb_devices WHERE LOWER(platform) = 'windows' AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-parallel
<!-- Initial Access and Execution Search -->
parallel:
- → webdav-script-leads
- → rundll32-ordinal-prevalence
join: → early-triage-agent

## webdav-script-leads
<!-- WebDAV and Interactive Script Leads -->
Identify scripts mounting WebDAV shares or running rundll32 from user-pasted commands.

```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Script blocks performing remote mounts or using rundll32. Silence means
  no such interactive script blocks were logged.
reads:
- device_hostname
- actor_user_name
- script_content
- time
silence: not_evidence_of_absence
source: hb_script_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(script_content) LIKE '%net use%' OR LOWER(script_content) LIKE '%dav%') AND (LOWER(script_content) LIKE '%rundll32%' OR LOWER(script_content) LIKE '%powershell%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## rundll32-ordinal-prevalence
<!-- Rundll32 Ordinal Execution Baseline -->
Identify rare rundll32.exe command lines using ordinal calls instead of function names.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: 'Rare command lines where rundll32 executes an export by its ordinal number
  (e.g., #1).'
prevalence:
  by: device_hostname
  key:
  - process_cmd_line
  rare_below: 5
reads:
- process_cmd_line
- device_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%rundll32.exe' AND process_cmd_line LIKE '%,#%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts < 5 ORDER BY hosts ASC
```

## early-triage-agent
<!-- Early Stage Evidence Review -->
```agent target=hunter
cite: required
context:
- webdav-script-leads
- rundll32-ordinal-prevalence
max_iterations: 3
objective: Determine if the host shows high-confidence signs of the UAT-10820 initial
  access and execution chain.
success_criteria: A per-host verdict of suspicious or malicious based on the presence
  of WebDAV scripts and rare rundll32 ordinal calls.
tools:
- endpoint
```

## follow-on-parallel
<!-- Follow-on Persistence and Driver Search -->
parallel:
- → rmm-persistence-hunt
- → vulnerable-driver-hunt
join: → chain-analysis-agent

## rmm-persistence-hunt
<!-- Unauthorized RMM Process Activity -->
Identify unauthorized remote access tools running from user-writable directories.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, rmm_filenames=rmm_filenames, lookback_days=lookback_days)
~~~yaml
expected: Processes associated with RMM tools running from non-standard, user-writable
  locations. None means no such processes were active.
reads:
- device_hostname
- process_name
- process_path
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\users\public\%') AND (instr(',' || '{{rmm_filenames}}' || ',', ',' || process_name || ',') > 0 OR LOWER(process_name) LIKE '%netsupport%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## vulnerable-driver-hunt
<!-- Vulnerable Driver Loads (BYOVD) -->
Identify loads of known vulnerable drivers used to bypass endpoint security.

```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts, vulnerable_drivers=vulnerable_drivers, lookback_days=lookback_days)
~~~yaml
expected: Loads of drivers like procexp.sys or iobitvdrv.sys that are commonly abused
  for EDR termination.
reads:
- device_hostname
- driver_path
- driver_signature_subject
- time
silence: not_evidence_of_absence
source: hb_kernel_extension_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, driver_path, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{vulnerable_drivers}}' || ',', ',' || LOWER(driver_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## chain-analysis-agent
<!-- Full Intrusion Chain Analysis -->
```agent target=hunter
cite: required
context:
- early-triage-agent
- rmm-persistence-hunt
- vulnerable-driver-hunt
max_iterations: 4
objective: Confirm if the identified host has been compromised by the UAT-10820 chain
  by linking early-stage findings with persistence markers.
success_criteria: A per-host verdict of Malicious | Suspicious | Benign, identifying
  which stage of the infection each host is in.
tools:
- endpoint
```

## route-decision
<!-- Route on Verdict -->
if~: "the chain-analysis-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: memory-only-stealers)
else: → analyst-review

## isolate-host
<!-- Isolate Endpoint -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately and collect forensic artifacts (memory and disk) for further investigation into Amatera stealer presence.
```
→ analyst-review

## analyst-review
<!-- Analyst Forensic Review -->
```manual target=analyst
Analyze the cited rundll32 command lines and RMM activity. Review hb_auth_signin for unusual logins from isolated hosts.
```
→ close-out

## close-out
<!-- Hunt Closeout -->
```manual target=analyst
Record the results and any tuning notes (e.g., legitimate IT use of NetSupport).
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.