Latest: CVE-2026-76504 Disclosed September 30 as Fourth SD-WAN Manager Flaw Since May
Cisco disclosed on September 30 that attackers are exploiting CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager's API session handling [2]. The flaw allows an unauthenticated remote attacker to access an affected system with privileges of the admin user, granting full control over the device and the SD-WAN fabric it manages [2]. The vulnerability stems from improper URI-encoding handling in HTTP requests, which lets a crafted request bypass an authentication rule protecting a specific API endpoint [4]. Cisco released fixed versions (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1) with no workaround available [2]. A system patched for the May or June SD-WAN advisories remains exposed to this flaw [2][5].
This brings the total to approximately eight Cisco SD-WAN entries added to CISA's Known Exploited Vulnerabilities (KEV) catalog in 2026 [5]. Across all Cisco product lines, approximately 12 CVEs with 2026 identifiers now sit in KEV, spanning SD-WAN, Secure Firewall Management Center (FMC), and ASA/FTD [20]. Since November 2021, CISA has cataloged a significant number of Cisco vulnerabilities as exploited in the wild, including multiple entries for Catalyst SD-WAN Manager [4].
UAT-8616: The Central Campaign Actor
Cisco Talos tracks the primary SD-WAN exploitation activity under the designation UAT-8616, describing the cluster as a "highly sophisticated cyber threat actor" [8][15]. The Australian Signals Directorate's Australian Cyber Security Centre (ASD-ACSC) reported the initial vulnerability, CVE-2026-20127, after observing real-world attacks [1][7]. According to available reporting, UAT-8616 has been exploiting CVE-2026-20127 in Cisco SD-WAN systems since at least 2023, with public disclosure occurring on February 25, 2026 [1][14].
Talos assessed that UAT-8616's infrastructure overlaps with Operational Relay Box (ORB) networks that Talos monitors separately [3]. The group targets network edge devices at high-value organizations such as critical national infrastructure operators [15]. While Talos has stopped short of country attribution, the targeting pattern of utilities and service providers could indicate nation-state backing [15]. Talos has not disclosed UAT-8616's motivation or ties to any previously named group [3].
The SD-WAN Authentication Bypass Chain: CVE-2026-20127 and CVE-2026-20182
CVE-2026-20127 (CVSS 10.0) is an authentication bypass in Cisco Catalyst SD-WAN Controller and Manager caused by a malfunctioning peering authentication mechanism [1]. An unauthenticated remote attacker can send a crafted request to bypass authentication, access the SD-WAN management plane, and manipulate the SD-WAN fabric configuration [1]. The flaw affects all deployment types: on-premises, Cisco Hosted SD-WAN Cloud, Cisco Managed, and FedRAMP environments [1][7].
Rapid7 researchers Jonah Burgess and Stephen Fewer discovered CVE-2026-20182 (CVSS 10.0) while analyzing CVE-2026-20127 [3][6]. Both flaws affect the vdaemon service over DTLS on UDP port 12346, but CVE-2026-20182 is a distinct issue, not a patch bypass [6]. Rapid7 found that when a connecting peer claims to be a vHub device, device-type-specific certificate verification does not occur, yet the code path still marks the peer as authenticated [9]. From that position, an attacker can inject an attacker-controlled SSH key into the vmanage-admin user account and perform privileged operations [6][8].
Cisco became aware of active exploitation of CVE-2026-20182 in May 2026 and published its advisory on May 14 [3][8]. CISA added the flaw to KEV with an accelerated remediation deadline [9]. Talos attributed exploitation to UAT-8616 with high confidence [13].
Post-compromise actions observed across both CVEs include: SSH key addition, NETCONF configuration modification, and escalation to root privileges [3][13].
Privilege Escalation: CVE-2026-20245, CVE-2026-20262, and CVE-2022-20775
UAT-8616's attack chain does not stop at admin access. The group chains authentication bypasses with privilege escalation flaws to reach root.
CVE-2022-20775 (CVSS 7.8): After exploiting CVE-2026-20127 for initial access, attackers downgraded the software version on compromised systems using the built-in update mechanism, then exploited this older CLI privilege escalation flaw to gain root before restoring the original firmware version [7][14]. CISA added CVE-2022-20775 to KEV alongside CVE-2026-20127 [1].
CVE-2026-20245 (CVSS 7.8): This flaw in the CLI of Catalyst SD-WAN Manager allows an authenticated local attacker to execute arbitrary commands as root by uploading a crafted file, exploiting insufficient input validation [11][12]. Mandiant discovered the vulnerability while investigating attacks on a service provider's SD-WAN infrastructure [10]. Mandiant identified two distinct periods of unauthorized activity: late 2025 through January 2026, and March 2026 [11]. Exploitation of CVE-2026-20245 specifically began as early as March 2026, roughly two months before Cisco's early June disclosure [10]. The attacker created a rogue troot account with full root-level access and accessed it from the admin account via the su command [12]. CISA added CVE-2026-20245 to KEV on June 4 with a June 23 deadline [10].
It is unclear whether the same threat actor conducted both waves of activity [11]. Throughout the intrusion, the threat actor "consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities" [11].
CVE-2026-20262: An arbitrary file-write flaw in the web UI of Catalyst SD-WAN Manager that lets an authenticated attacker overwrite files on the underlying OS and escalate to root [16][17]. Cisco found the vulnerability internally and confirmed exploitation in June 2026 [17]. It was the seventh SD-WAN CVE flagged by CISA as exploited that year [16].
Additional Exploitation Clusters on SD-WAN
Talos identified threat actors distinct from UAT-8616 exploiting a different set of SD-WAN vulnerabilities beginning March 2026: CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 [13]. These CVEs had patches available since February 2026 [13]. Two clusters were identified: Cluster 1 active since at least March 6, and Cluster 2 since at least March 10 [13]. The majority of this exploitation used ZeroZenX Labs' proof-of-concept code and an accompanying JSP-based webshell that Talos tracks as "XenShell" [13]. Post-compromise tooling included Godzilla and Behinder webshells, Sliver and AdaptixC2 implants, and XMRig for cryptocurrency mining [13].
Cisco Secure Firewall Management Center: CVE-2026-20316 and CVE-2026-20079
The exploitation campaign extended beyond SD-WAN into FMC products.
CVE-2026-20316 (CVSS 5.3 base score, rated High by Cisco's Security Impact Rating): A static-credential vulnerability in FMC Software. An unauthenticated remote attacker can use built-in credentials for a low-privilege account to log in and access sensitive data [18][19]. Cisco raised the severity rating because the access can be combined with other FMC flaws to escalate privileges, though Cisco has not identified the additional vulnerabilities used [19]. CISA added it to KEV on July 29 with an August 1 deadline [18]. Jimi Sebree of Horizon3.ai reported the flaw [19].
CVE-2026-20079 (CVSS 10.0): An authentication bypass in the FMC web interface that lets an unauthenticated remote attacker bypass authentication and execute script files to obtain root access [23]. Originally disclosed in March 2026, Cisco updated the advisory on July 29 to add exploitation details and IOCs [19]. Cisco identified three post-compromise clusters on FMC instances: UAT-12197, UAT-11823, and UAT-11988, all deploying web shells and malware [23]. CISA added it to KEV on September 10 with a September 12 deadline [23].
Cisco ASA/FTD: CVE-2026-20349
CVE-2026-20349 (CVSS 8.6) is a heap inspection vulnerability in the Remote Access SSL VPN service of ASA and FTD software [21]. The root cause is insufficient error handling when processing crafted HTTP requests, causing the device to reload (denial of service) [21][22]. Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD [22]. Cisco became aware of active exploitation in August 2026 [22]. CISA added it to KEV on August 11 with an August 14 deadline [20][21]. This is the third time in three years that Cisco's firewall line has landed in KEV as a zero-day, following the 2024 ArcaneDoor campaign [21].
Indicators of Compromise
The following IOCs are drawn verbatim from source material. Organizations should cross-reference against their own telemetry.
| Type | Value | Context | Source |
|---|---|---|---|
| IP | 176.65.139.31 |
SD-WAN exploitation cluster, Nim backdoor/kscan | [13] |
| IP | 38.181.52.89 |
Exploit interaction with shell | [13] |
| IP | 89.125.244.33 |
Exploit interaction with shell | [13] |
| IP | 89.125.244.51 |
Exploit interaction with shell | [13] |
| IP | 71.80.85.135 |
SD-WAN exploitation, base64-only variant | [13] |
| IP | 212.83.162.37 |
Behinder webshell deployment | [13] |
| IP | 38.60.214.92 |
Godzilla webshell deployment | [13] |
| IP | 65.20.67.134 |
Godzilla webshell deployment | [13] |
| IP | 104.233.156.1 |
Godzilla webshell deployment | [13] |
| IP | 194.233.100.40 |
Godzilla webshell deployment | [13] |
| IP | 194.163.175.135 |
AdaptixC2 agent C2 | [13] |
| IP | 23.27.143.170 |
Sliver C2 | [13] |
| IP | 83.229.126.195 |
Payload hosting (XMRig) | [13] |
| IP | 13.62.52.206 |
C2 server for agent tool (note: cloud provider IP range, validate with date context) | [13] |
| IP | 79.135.105.208 |
Attacker source IP | [13] |
| IP | 47.104.248.7 |
Miner-related activity | [13] |
| Domain | 1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev |
Nim backdoor download | [13] |
| Filename | 20251117022131.jsp |
Godzilla webshell | [13] |
| Filename | conf.jsp |
Behinder webshell | [13] |
| Filename | sysv.jsp |
XenShell | [13] |
| Filename | sysinit.jsp |
Behinder webshell | [13] |
| Filename | vmurnp_ikp.jsp |
Godzilla webshell | [13] |
| Filename | defunct.dat |
C2 peer config file | [13] |
| Filename | miner.sh |
Moneroocean miner script | [13] |
| Filename | loot_run.sh |
Credential stealer script | [13] |
| Filename | vconfd_script_upload_tenant_list.sh |
Unauthorized script execution during CVE-2026-20245 exploitation | |
| Filename | serviceproxy-access.log |
Log file for CVE-2026-76504 investigation (under /var/log/nms/containers/service-proxy) |
[4] |
| Filename | vmanage-server.log |
Log file for CVE-2026-76504 investigation (under /var/log/nms/) |
[4] |
| Malware | XenShell | JSP webshell, ZeroZenX Labs PoC-derived | [13] |
| Malware | Godzilla Webshell | Post-compromise persistence | [13] |
| Malware | Behinder | Post-compromise webshell | [13] |
Note: The domain a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev (without leading '1') appeared in an earlier version of this table but is assessed to be a transcription error of the entry above. Analysts should verify both variants against source [13] before operationalizing.
MITRE ATT&CK Mapping
| Technique ID | Name | Context |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial access via CVE-2026-20127, CVE-2026-20182, CVE-2026-76504, CVE-2026-20079, CVE-2026-20349 |
| T1098.004 | Account Manipulation: SSH Authorized Keys | SSH key injection into vmanage-admin and root accounts[13] |
| T1078 | Valid Accounts | Use of static credentials (CVE-2026-20316) and manipulated admin passwords [19] |
| T1068 | Exploitation for Privilege Escalation | CVE-2026-20245, CVE-2022-20775, CVE-2026-20262 for root access [10][14][16] |
| T1601.002 | Modify System Image: Downgrade to Insecure Version | Firmware downgrade to exploit CVE-2022-20775 [14] |
| T1505.003 | Server Software Component: Web Shell | XenShell, Godzilla, Behinder deployment [13] |
| T1136.001 | Create Account: Local Account | Creation of rogue troot account [12] |
| T1021.004 | Remote Services: SSH | SSH access via injected keys and rogue peering |
| T1070.002 | Indicator Removal: Clear Linux or Mac System Logs | Clearing logs in /var/log, command history [14] |
| T1070.003 | Indicator Removal: Clear Command History | Deletion of command history post-exploitation [14] |
| T1070 | Indicator Removal | Reverting configuration changes and clearing connection logs [11][14] |
| T1090.003 | Proxy: Multi-hop Proxy | ORB network infrastructure overlap [3] |
| T1037.004 | Boot or Logon Initialization Scripts: RC Scripts | Modification of startup scripts on Linux-based appliances post-compromise [14] |
SD-WAN Peering Anomalies
Run show control connections detail and show control connections-history detail on SD-WAN controllers. Flag peer entries with state:up combined with challenge-ack:0, peers claiming device type 2 (vHub) where no vHub is deployed, and peering events outside documented maintenance windows. Cross-reference against authorized peer inventories.
SSH Key and Account Monitoring
Monitor /home/vmanage-admin/.ssh/authorized_keys and /home/root/.ssh/authorized_keys for additions, modifications, or deletions. On Linux-based appliances, auditd path watches or EDR file-integrity monitoring can generate alerts. Review SD-WAN Manager user audit logs and vsyslog for system-login-change notifications, particularly for unexpected root sessions.
CVE-2026-76504 Detection
Search serviceproxy-access.log (located at /var/log/nms/containers/service-proxy) and vmanage-server.log (under /var/log/nms/) for entries related to j_security_check from unknown or unauthorized IP addresses [4]. The confirmed IOC is the use of %6a as the URI-encoded character "j" in malicious requests targeting the API [4].
# Sigma Rule: CVE-2026-76504 URI-Encoding Bypass Attempt
title: Cisco SD-WAN Manager CVE-2026-76504 URI Encoding Bypass
id: a3f8d1e0-7c42-4b9e-a1d3-5e8f9b2c4d6a
status: experimental
author: RedSheepSec
date: 2026/09/30
description: Detects URI-encoded bypass attempts against Cisco SD-WAN Manager API using percent-encoded characters in j_security_check requests
logsource:
category: webserver
product: cisco_sdwan
detection:
selection:
cs-uri-stem|contains: '%6a'
cs-uri-stem|contains: 'security_check'
condition: selection
falsepositives:
- Legitimate API clients that percent-encode lowercase ASCII (unlikely for this path)
level: high
tags:
- attack.initial_access
- attack.t1190
- cve.2026.76504
FMC Static Credential Exploitation
For CVE-2026-20316, review /var/log/messages on FMC appliances for authentication events from the static low-privilege account originating from unexpected source IPs [19]. Restrict the FMC management interface from public internet access [18].
ASA/FTD SSL VPN Crash Detection
For CVE-2026-20349, monitor for unexpected device reloads on ASA/FTD appliances with SSL VPN, IKEv2 Remote Access VPN, or ZTNA enabled [22]. Correlate reload events with HTTP request logs to the VPN service from external sources.
Webshell Detection
Hunt for JSP files in SD-WAN Manager web application directories, particularly the filenames listed in the IOC table (sysv.jsp, conf.jsp, sysinit.jsp, vmurnp_ikp.jsp, 20251117022131.jsp) [13]. The path-traversal pattern deploying cmd.gz.war via the software upload endpoint is another high-fidelity indicator [25].
Analysis
The sustained exploitation of Cisco SD-WAN products through 2026 follows a clear operational pattern. UAT-8616 targets the peering authentication mechanism to establish rogue peers in the SD-WAN management plane, then chains privilege escalation flaws to achieve root access and maintain persistence [14][16]. The group's use of ORB network infrastructure [3], its targeting of critical infrastructure operators [15], and its multi-year dwell time (reportedly dating to 2023) [1][14] are consistent with a state-sponsored intelligence collection mission, though Talos has not confirmed attribution to any country.
Separately, at least two additional exploitation clusters have targeted the same SD-WAN product line using publicly available PoC code from ZeroZenX Labs, deploying commodity tooling (XMRig, Sliver, Godzilla) for what appears to be financially motivated objectives [13]. The coexistence of a probable state actor and opportunistic criminal clusters on the same vulnerable product set complicates incident response: organizations cannot assume a single attacker profile.
The expansion into FMC (CVE-2026-20316, CVE-2026-20079) and ASA/FTD (CVE-2026-20349) products indicates that adversary interest is not limited to SD-WAN. Three distinct FMC exploitation clusters (UAT-12197, UAT-11823, UAT-11988) deploying web shells and malware represent additional, separately tracked threat activity [23].
Mandiant's finding that CVE-2026-20245 was exploited roughly two months before disclosure [10], combined with UAT-8616's reported multi-year exploitation of CVE-2026-20127 before its February 2026 disclosure [1][14], points to a pattern where adversaries likely possess undisclosed Cisco vulnerabilities for extended periods. The limited forensic telemetry available on edge network appliances compounds the problem [11].
Red Sheep Assessment
Confidence: Moderate
The aggregate pattern of approximately 12 exploited Cisco CVEs added to KEV in a single calendar year, spanning three product families, with at least two confirmed zero-day exploitation windows measured in months rather than days, suggests that adversaries likely have additional undisclosed Cisco vulnerabilities beyond what has surfaced publicly. The September 30 disclosure of CVE-2026-76504, coming as the fourth SD-WAN Manager flaw since May with each requiring separate patching [2][5], indicates a product attack surface that repeated patching cycles have not fully addressed.
The Five Eyes joint advisory involvement [15] and Emergency Directive 26-03 signal that allied intelligence agencies assess UAT-8616 as a significant national security threat. The deliberate avoidance of public attribution, combined with the ORB infrastructure overlap and critical infrastructure targeting, is consistent with a well-resourced state actor. No cited source has attributed UAT-8616 to a specific country, and multiple state actors possess comparable capabilities. Alternative explanations including contracted operators or proxy groups cannot be excluded from available reporting.
An alternative interpretation: the volume of CVEs may partly reflect improved detection and reporting rather than a net increase in adversary capability. CISA's more aggressive KEV posture since 2024 means flaws that might have gone uncataloged in prior years now receive formal tracking. This does not diminish the operational risk, but defenders should calibrate their assessment of whether adversary velocity has truly increased or whether visibility has improved.
Organizations running any Cisco network edge product should treat this as an ongoing campaign requiring continuous hunting, not a sequence of discrete patch cycles.
Defender's Checklist
- ▢[ ] Patch CVE-2026-76504 immediately. Upgrade Catalyst SD-WAN Manager to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Systems patched for May/June advisories are still exposed [2][5]. Restrict Manager API access to trusted hosts until upgraded [2].
- ▢[ ] Hunt for rogue peering on all SD-WAN controllers. Run
show control connections detailandshow control connections-history detail. Flag any peer claiming vHub device type where no vHub exists, and any peering event withchallenge-ack:0. Audit against your authorized peer inventory.
- ▢[ ] Inspect SD-WAN Manager logs for CVE-2026-76504 exploitation. Search
serviceproxy-access.logandvmanage-server.logforj_security_checkrequests containing%6afrom unauthorized IPs [4].
- ▢[ ] Audit SSH authorized_keys on all SD-WAN controllers and managers. Check
/home/vmanage-admin/.ssh/authorized_keysand/home/root/.ssh/authorized_keysfor unauthorized keys. Cross-reference with the Five Eyes threat hunt guide.
- ▢[ ] Apply FMC hot fixes and restrict management interfaces. Patch CVE-2026-20316 and CVE-2026-20079 on all Secure FMC instances. Review
/var/log/messagesfor static-credential authentication from unexpected sources. Block FMC management from public internet access [18][19].
References
[1] https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html
[2] https://dev.to/etairos/cisco-sd-wan-manager-zero-day-cve-2026-76504-grants-unauthenticated-admin-api-access-2i0o
[3] https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/
[4] https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
[5] https://github.com/Xore/APIARY/issues/3488
[6] https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.html
[7] https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-vulnerability-exploited-in-the-wild-cve-2026-20127/
[8] https://beazley.security/alerts-advisories/critical-vulnerability-in-cisco-catalyst-sd-wan-controller-under-active-exploitation-cve-2026-20182
[9] https://socprime.com/blog/cve-2026-20182-analysis/
[10] https://www.darkreading.com/cyberattacks-data-breaches/attackers-hit-cisco-sd-wan-flaw-2-months-before-disclosure
[11] https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html
[12] https://securityaffairs.com/194200/hacking/cisco-catalyst-sd-wan-zero-day-cve-2026-20245-exploited-months-before-disclosure.html
[13] https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
[14] https://www.avertium.com/flash-notices/uat-8616-exploits-cisco-sd-wan-zero-day-for-persistent-access
[15] https://www.computerweekly.com/news/366639459/Cisco-Catalyst-SD-WAN-users-targeted-in-series-of-cyber-attacks
[16] https://tech-insider.org/cisco-sd-wan-vulnerability-2026/
[17] https://www.hendryadrian.com/cisco-patches-another-sd-wan-zero-day-exploited-in-attacks/
[18] https://socprime.com/blog/cve-2026-20316-cisco-fmc-zero-day-exploited/
[19] https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
[20] https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/
[21] https://tech-insider.org/cisco-asa-ftd-zero-day-cve-2026-20349/
[22] https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
[23] https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html
[24] https://securityarsenal.com/blog/uat-8616-interlock-and-the-gentlemen-cisco-edge-exploitation-sliver-c2-and-plasmaloader-otx-pulse-analysis
[25] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
Event Timeline
Timeline
Entity Relationships
Entity Graph (39 entities, 68 relationships)
Diamond Model
Diamond Model
Hunt Guide: UAT-8616 and Associated Clusters Exploiting Cisco SD-WAN, FMC, and ASA/FTD Product Lines
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If UAT-8616 or associated exploitation clusters have compromised Cisco network edge devices in our environment, we expect to observe network connections to known C2 infrastructure, exploitation artifacts such as URI-encoded authentication bypass attempts, webshell filenames on application servers, unauthorized SSH key modifications, rogue account creation, and post-compromise tooling (Sliver, Godzilla, Behinder, XMRig) across firewall logs, network metadata, endpoint telemetry, and web server access logs.
Intelligence Summary: Cisco Talos tracks UAT-8616 as the primary actor exploiting Cisco Catalyst SD-WAN authentication bypass and privilege escalation vulnerabilities since at least 2023, with infrastructure overlapping Operational Relay Box (ORB) networks and targeting critical infrastructure operators. Approximately 12 Cisco CVEs with 2026 identifiers have been added to CISA's KEV catalog spanning SD-WAN Manager, Secure Firewall Management Center (FMC), and ASA/FTD product lines, with multiple zero-day exploitation windows measured in months. At least two additional exploitation clusters distinct from UAT-8616 have targeted SD-WAN using publicly available proof-of-concept code, deploying commodity tooling including XMRig, Sliver, Godzilla, and Behinder webshells for what appears to be financially motivated objectives.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All network segments containing Cisco Catalyst SD-WAN controllers and managers, Cisco Secure Firewall Management Center (FMC) instances, and Cisco ASA/FTD appliances. Include management VLANs and any segments with DTLS peering (UDP 12346) exposure.
- Timeframe: February 2026 through present (October 2026). UAT-8616 activity reportedly dates to 2023, so extend lookback to January 2023 for SSH key and account anomaly analysis on SD-WAN infrastructure if log retention permits.
- Priority Systems: Cisco Catalyst SD-WAN Manager and Controller instances (all deployment types including on-premises, Cisco Hosted, Cisco Managed, and FedRAMP), Cisco Secure FMC appliances, and Cisco ASA/FTD devices with SSL VPN, IKEv2 RA VPN, or ZTNA enabled. FedRAMP-hosted SD-WAN environments are explicitly in scope per Cisco advisory.
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
UAT-8616 and additional clusters exploit authentication bypass vulnerabilities in Cisco SD-WAN Manager (CVE-2026-20127, CVE-2026-20182, CVE-2026-76504), FMC (CVE-2026-20079), and ASA/FTD (CVE-2026-20349) to gain initial access. CVE-2026-76504 uses URI-encoded %6a in j_security_check requests to bypass authentication. CVE-2026-20182 exploits DTLS peering on UDP 12346 by claiming vHub device type. Exploitation clusters also used CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 via ZeroZenX Labs PoC code.
Splunk SPL:
index=corelight sourcetype=corelight_http (uri="*%6a*" AND uri="*security_check*") OR (uri="*j_security_check*") | stats count by id.orig_h, id.resp_h, id.resp_p, uri, method, status_code | sort -count | table id.orig_h, id.resp_h, id.resp_p, uri, method, status_code, count
Elastic KQL:
url.path:(*%6a* AND *security_check*) OR url.path:*j_security_check* OR destination.port:12346
Sigma Rule:
title: Cisco SD-WAN Manager CVE-2026-76504 URI Encoding Bypass
id: a3f8d1e0-7c42-4b9e-a1d3-5e8f9b2c4d6a
status: experimental
author: RedSheepSec
date: 2026/09/30
description: Detects URI-encoded bypass attempts against Cisco SD-WAN Manager API using percent-encoded characters in j_security_check requests
logsource:
category: webserver
detection:
selection:
cs-uri-stem|contains|all:
- '%6a'
- 'security_check'
condition: selection
falsepositives:
- Legitimate API clients that percent-encode lowercase ASCII (unlikely for this path)
level: high
tags:
- attack.initial_access
- attack.t1190
The %6a URI encoding bypass is a high-fidelity indicator for CVE-2026-76504. Also monitor UDP 12346 (DTLS peering) for unexpected connections to SD-WAN controllers. Correlate with firewall deny/allow logs for external sources connecting to SD-WAN management interfaces.
T1098.004: Account Manipulation: SSH Authorized Keys (Persistence) [P2]
After initial access via CVE-2026-20182, attackers inject SSH keys into the vmanage-admin and root authorized_keys files on compromised SD-WAN controllers and managers. This provides persistent access independent of password changes.
Splunk SPL:
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=linux_audit) (key="authorized_keys" OR name="*authorized_keys*" OR path="*/home/vmanage-admin/.ssh/authorized_keys*" OR path="*/home/root/.ssh/authorized_keys*" OR path="*/root/.ssh/authorized_keys*") | stats count by host, path, syscall, exe, auid | sort -count
Elastic KQL:
file.path:(*authorized_keys*) AND (event.action:"opened-for-write" OR event.action:"created" OR event.action:"modified")
Sigma Rule:
title: SSH Authorized Keys Modification on Network Appliance
id: b4c7e2f1-8d53-4a0f-b2e4-6f9a0c3d5e7b
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects modifications to SSH authorized_keys files, which may indicate persistence via SSH key injection as observed in UAT-8616 campaigns against Cisco SD-WAN
logsource:
product: linux
category: file_change
detection:
selection:
TargetFilename|endswith: 'authorized_keys'
filter_maintenance:
User|contains:
- 'ansible'
- 'puppet'
condition: selection and not filter_maintenance
falsepositives:
- Legitimate SSH key provisioning by automation tools
- Administrator key rotation
level: high
tags:
- attack.persistence
- attack.t1098.004
Filter out known automation accounts (Ansible, Puppet, Chef) that legitimately manage SSH keys. Correlate with user session logs to determine if a human initiated the change. On SD-WAN appliances, auditd coverage may be limited; check vendor documentation.
T1078: Valid Accounts (Initial Access) [P2]
CVE-2026-20316 exposes static built-in credentials in Cisco FMC Software. An unauthenticated remote attacker can use these credentials to log in as a low-privilege account and access sensitive data. Combined with other FMC flaws, this can escalate to full control.
Splunk SPL:
index=firewall-pan sourcetype="pan:traffic:aggregated" dest_port=443 action=allowed (dest_ip IN ("<FMC_MGMT_IP_1>", "<FMC_MGMT_IP_2>")) NOT src_ip IN ("<TRUSTED_MGMT_SUBNET>") | stats count by src_ip, dest_ip, dest_port | where count > 3 | sort -count
Replace <FMC_MGMT_IP_*> and <TRUSTED_MGMT_SUBNET> with local values |
|---|
**Elastic KQL:**
destination.port:443 AND destination.ip:(<FMC_MGMT_IPs>) AND NOT source.ip:(<trusted_management_ranges>)
**Sigma Rule:**
title: Unauthorized Access to Cisco FMC Management Interface
id: c5d8f3a2-9e64-4b1f-c3f5-7a0b1d4e6f8c
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects connections to Cisco FMC management interfaces from non-trusted source IPs, relevant to CVE-2026-20316 static credential exploitation
logsource:
category: firewall
detection:
selection:
dst_port: 443
dst_ip|cidr:
- '<FMC_MGMT_SUBNET>'
filter_trusted:
src_ip|cidr:
- '<TRUSTED_MGMT_SUBNET>'
condition: selection and not filter_trusted
falsepositives:
- Vendor support access from approved IPs
level: medium
tags:
- attack.initial_access
- attack.t1078
*This detection requires populating FMC management IP addresses and trusted management subnets. FMC management interfaces should never be internet-exposed. If they are, treat any external connection as high priority.*
#### T1068: Exploitation for Privilege Escalation (Privilege Escalation) [P1]
After authentication bypass, UAT-8616 chains CVE-2026-20245, CVE-2022-20775, and CVE-2026-20262 to escalate from admin to root on SD-WAN Manager. CVE-2026-20245 involves uploading a crafted file via CLI. CVE-2022-20775 is a CLI privilege escalation exploited after firmware downgrade. CVE-2026-20262 uses arbitrary file write via the web UI.
**Splunk SPL:**
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=linux_audit) (exe="/su" OR exe="/sudo") (key="privilege_escalation" OR auid!="0") | search (comm="su" AND (terminal="*" AND auid!="0")) | stats count by host, auid, uid, exe, comm, terminal | sort -count
**Elastic KQL:**
process.name:("su" OR "sudo") AND user.name:"admin" AND event.category:"process"
**Sigma Rule:**
title: Rogue troot Account Creation on Linux Appliance
id: d6e9f4b3-0a75-4c2f-d4a6-8b1c2e5f7a9d
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects creation of the troot account observed in UAT-8616 post-exploitation of Cisco SD-WAN CVE-2026-20245
logsource:
product: linux
category: process_creation
detection:
selection_useradd:
Image|endswith:
- '/useradd'
- '/adduser'
CommandLine|contains: 'troot'
selection_usermod:
Image|endswith: '/usermod'
CommandLine|contains: 'troot'
condition: selection_useradd or selection_usermod
falsepositives:
- Legitimate account named troot (unlikely in standard deployments)
level: critical
tags:
- attack.privilege_escalation
- attack.t1068
- attack.t1136.001
*The troot account is a specific IOC from Mandiant's investigation. Also monitor for the script vconfd_script_upload_tenant_list.sh, which was observed during CVE-2026-20245 exploitation.*
#### T1601.002: Modify System Image: Downgrade to Insecure Version (Defense Evasion) [P2]
UAT-8616 downgraded firmware on compromised SD-WAN systems using the built-in update mechanism to exploit CVE-2022-20775, then restored the original version after gaining root. This technique makes post-incident forensics difficult and exploits older, patched vulnerabilities.
**Splunk SPL:**
index=linux-server (sourcetype=linux:secure OR sourcetype=linux_secure OR sourcetype=syslog) ("software" AND ("upgrade" OR "downgrade" OR "install" OR "update")) | stats count by host, _raw | sort -count | head 50
**Elastic KQL:**
message:(software AND (downgrade OR upgrade OR install)) AND host.os.type:"linux"
*Firmware version changes on SD-WAN appliances outside of scheduled maintenance windows are high-priority anomalies. Correlate with change management tickets. Native SD-WAN CLI commands (show software) provide authoritative version information.*
#### T1505.003: Server Software Component: Web Shell (Persistence) [P1]
Multiple exploitation clusters deploy JSP-based webshells on compromised SD-WAN Manager and FMC instances. Named webshells include XenShell (sysv.jsp), Godzilla (20251117022131.jsp, vmurnp_ikp.jsp), and Behinder (conf.jsp, sysinit.jsp). A path-traversal pattern deploying cmd.gz.war via the software upload endpoint is also observed.
**Splunk SPL:**
index=corelight sourcetype=corelight_http (uri="sysv.jsp" OR uri="conf.jsp" OR uri="sysinit.jsp" OR uri="vmurnp_ikp.jsp" OR uri="20251117022131.jsp" OR uri="cmd.gz.war" OR uri="deploymentscmd*") | stats count by id.orig_h, id.resp_h, uri, method, status_code | sort -count
**Elastic KQL:**
url.path:(sysv.jsp OR conf.jsp OR sysinit.jsp OR vmurnp_ikp.jsp OR 20251117022131.jsp OR cmd.gz.war)
**Sigma Rule:**
title: Cisco SD-WAN Webshell Filenames in HTTP Requests
id: e7f0a5c4-1b86-4d3f-e5b7-9c2d3f6a8b0e
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects HTTP requests referencing known webshell filenames deployed during Cisco SD-WAN exploitation campaigns (XenShell, Godzilla, Behinder)
logsource:
category: webserver
detection:
selection:
cs-uri-stem|contains:
- 'sysv.jsp'
- 'conf.jsp'
- 'sysinit.jsp'
- 'vmurnp_ikp.jsp'
- '20251117022131.jsp'
- 'cmd.gz.war'
condition: selection
falsepositives:
- Legitimate applications with coincidentally named JSP files (very unlikely for these specific names)
level: critical
tags:
- attack.persistence
- attack.t1505.003
*These filenames are high-fidelity IOCs. Also hunt for any .jsp files in unexpected directories on SD-WAN Manager servers, particularly under WildFly deployment paths. The path-traversal URI pattern containing deployments/cmd.gz.war is an additional indicator.*
#### T1136.001: Create Account: Local Account (Persistence) [P1]
Attackers created a rogue troot account with full root-level access on compromised SD-WAN Manager systems, then accessed it from the admin account via the su command.
**Splunk SPL:**
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=linux_audit OR sourcetype=linux_secure OR sourcetype=linux:secure) ("useradd" OR "adduser" OR "troot") | stats count by host, _raw | sort -count
**Elastic KQL:**
process.name:("useradd" OR "adduser") OR user.name:"troot" OR process.args:"troot"
*The troot account name is a direct IOC. Any local account creation on network appliances that is not documented in change management should trigger investigation.*
#### T1021.004: Remote Services: SSH (Lateral Movement) [P2]
After injecting SSH keys, UAT-8616 accesses compromised SD-WAN controllers and managers via SSH, including through rogue peering relationships. SSH sessions from unexpected source IPs or using injected keys indicate compromise.
**Splunk SPL:**
index=corelight sourcetype=corelight_ssh (auth_success="true") | stats count dc(id.orig_h) as unique_sources by id.resp_h, id.resp_p | where unique_sources > 3 OR id.resp_p!=22 | sort -unique_sources
**Elastic KQL:**
event.dataset:"corelight.ssh" AND ssh.auth.success:true
*Baseline normal SSH sources to SD-WAN infrastructure. Any SSH session from a non-management subnet is suspicious. Also monitor for SSH on non-standard ports.*
#### T1070.002: Indicator Removal: Clear Linux or Mac System Logs (Defense Evasion) [P2]
UAT-8616 consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files and clearing logs in /var/log and command history during post-exploitation.
**Splunk SPL:**
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=linux_audit) (key="log_deletion" OR (syscall IN ("unlink","unlinkat","rename") AND (name="/var/log/" OR name="history" OR name="auth.log" OR name="syslog"))) | stats count by host, exe, name, syscall | sort -count
**Elastic KQL:**
event.action:("unlink" OR "delete" OR "rename") AND file.path:(/var/log/ OR history*) AND host.os.type:"linux"
**Sigma Rule:**
title: Log Deletion on Linux Network Appliance
id: f8a1b6d5-2c97-4e4f-f6c8-0d3e4a7b9c1f
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects deletion of log files and command history on Linux systems, consistent with anti-forensic techniques used by UAT-8616 post-exploitation
logsource:
product: linux
category: file_delete
detection:
selection_logs:
TargetFilename|startswith: '/var/log/'
selection_history:
TargetFilename|contains:
- '.bash_history'
- '.history'
- 'auth.log'
condition: selection_logs or selection_history
falsepositives:
- Log rotation (logrotate) - filter by process name
- Automated cleanup scripts
level: high
tags:
- attack.defense_evasion
- attack.t1070.002
- attack.t1070.003
*Filter out logrotate and known cron-based cleanup processes. Focus on deletions by interactive user sessions or processes running as admin/root outside of scheduled rotation.*
#### T1090.003: Proxy: Multi-hop Proxy (Command and Control) [P1]
Talos assessed that UAT-8616's infrastructure overlaps with Operational Relay Box (ORB) networks. ORB networks use chains of compromised devices as relay nodes to obscure the origin of C2 traffic.
**Splunk SPL:**
index=corelight sourcetype=corelight_conn (id.resp_p=443 OR id.resp_p=8443 OR id.resp_p=8080 OR id.resp_p=5004) (id.resp_h="176.65.139.31" OR id.resp_h="194.163.175.135" OR id.resp_h="23.27.143.170" OR id.resp_h="13.62.52.206" OR id.resp_h="83.229.126.195") | stats sum(orig_bytes) as bytes_out sum(resp_bytes) as bytes_in count by id.orig_h, id.resp_h, id.resp_p | sort -count
**Elastic KQL:**
destination.ip:("176.65.139.31" OR "194.163.175.135" OR "23.27.143.170" OR "13.62.52.206" OR "83.229.126.195") AND destination.port:(443 OR 8443 OR 8080 OR 5004)
*ORB infrastructure IPs rotate frequently. This query uses known IOCs from the Talos report. Supplement with threat intel feeds for updated ORB indicators.*
#### T1037.004: Boot or Logon Initialization Scripts: RC Scripts (Persistence) [P2]
Post-compromise, UAT-8616 modified startup scripts on Linux-based SD-WAN appliances to maintain persistence across reboots.
**Splunk SPL:**
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=linux_audit) (name="/etc/rc.local" OR name="/etc/init.d/" OR name="/etc/rc.d/" OR name="/etc/systemd/system/*") (syscall IN ("open","openat","write","rename","unlink")) | stats count by host, name, exe, auid, syscall | sort -count
**Elastic KQL:**
file.path:(/etc/rc.local OR /etc/init.d/ OR /etc/rc.d/ OR /etc/systemd/system/) AND event.action:("opened-for-write" OR "created" OR "modified")
*Modifications to startup scripts on network appliances should be rare outside of firmware updates. Any change not correlated with a vendor update or documented change ticket warrants investigation.*
### Indicators of Compromise
| Type | Value | Context |
|------|-------|---------|
| ip | `176.65.139.31` | SD-WAN exploitation cluster, Nim backdoor/kscan IP \| AbuseIPDB confidence 0% (1 reports, DE) |
| ip | `38.181.52.89` | Exploit interaction with shell on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, SG) |
| ip | `89.125.244.33` | Exploit interaction with shell on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, JP) |
| ip | `89.125.244.51` | Exploit interaction with shell on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, JP) |
| ip | `71.80.85.135` | SD-WAN exploitation, base64-only variant \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `212.83.162.37` | Behinder webshell deployment on compromised SD-WAN \| AbuseIPDB confidence 0% (42 reports, FR) |
| ip | `38.60.214.92` | Godzilla webshell deployment on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, TW) |
| ip | `65.20.67.134` | Godzilla webshell deployment on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, IN) |
| ip | `104.233.156.1` | Godzilla webshell deployment on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, KR) |
| ip | `194.233.100.40` | Godzilla webshell deployment on compromised SD-WAN \| AbuseIPDB confidence 0% (0 reports, JP) |
| ip | `194.163.175.135` | AdaptixC2 agent C2 server \| AbuseIPDB confidence 0% (0 reports, FR) |
| ip | `23.27.143.170` | Sliver C2 server \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `83.229.126.195` | Payload hosting (XMRig), served xmrig binary and config.json on port 8081 \| AbuseIPDB confidence 8% (3 reports, HK) |
| ip | `13.62.52.206` | C2 server for agent tool on port 5004 (cloud provider IP, validate with date context) \| AbuseIPDB confidence 0% (0 reports, SE) |
| ip | `79.135.105.208` | Attacker source IP in SD-WAN compromise \| AbuseIPDB confidence 0% (1 reports, FR) |
| ip | `47.104.248.7` | Miner-related activity in SD-WAN exploitation cluster \| AbuseIPDB confidence 0% (0 reports, CN) |
| domain | `1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev` | Download URL for Nim-based backdoor in SD-WAN exploitation cluster \| VirusTotal 11/91 malicious |
| domain | `a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev` | Possible transcription variant of Nim backdoor download domain; verify both variants \| VirusTotal 8/91 malicious |
| hash_sha256 | `d94f75a70b5cabaf786ac57177ed841732e62bdcc9a29e06e5b41d9be567bcfa` | SD-WAN cluster 9 gsocket hash (VirusTotal 42/75 malicious) \| VirusTotal 42/75 malicious (hacktool.gsnetcat/gsocket) |
| hash_sha256 | `02654acfb21f83485393ba8b14bd8862b919b9ec966fc6768f6aac1338a45ee8` | SD-WAN cluster 6 Sliver implant hash (VirusTotal 32/75 malicious) \| VirusTotal 32/75 malicious (trojan.sliver/yxgc5z) |
| hash_sha256 | `96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46` | SD-WAN cluster 7 XMRig miner sample (VirusTotal 39/75 malicious) \| VirusTotal 39/75 malicious (miner.xmrig/bitcoinmi) |
| hash_sha256 | `18d77c9c5bbb5b9d5bdfd366fdfcf26bad9e64c63ca865fad711bcce8e3d5a80` | SD-WAN cluster 8 kscan scanning tool (VirusTotal 33/74 malicious) \| VirusTotal 33/74 malicious (trojan.exploitscan/railgun) |
| hash_sha256 | `3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235` | UAT-8616 Cisco edge intrusion hash \| VirusTotal 49/75 malicious (ransomware.gentlemen/gentleman) |
| hash_sha256 | `51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2` | UAT-8616 Cisco edge intrusion hash \| VirusTotal 51/75 malicious (trojan.razr/casdet) |
| hash_md5 | `4200b46a93c6ab059e2b34ce200c4a5b` | Payload hash in UAT-8616/Gentlemen Cisco edge campaign \| VirusTotal 49/75 malicious (ransomware.gentlemen/gentleman) |
| filename | `20251117022131.jsp` | Godzilla webshell deployed post-exploitation on SD-WAN |
| filename | `conf.jsp` | Behinder webshell deployed post-exploitation on SD-WAN |
| filename | `sysv.jsp` | XenShell webshell deployed post-exploitation on SD-WAN |
| filename | `sysinit.jsp` | Behinder webshell deployed post-exploitation on SD-WAN |
| filename | `vmurnp_ikp.jsp` | Godzilla webshell deployed post-exploitation on SD-WAN |
| filename | `defunct.dat` | C2 peer config file used by SD-WAN implant |
| filename | `miner.sh` | Moneroocean miner script in SD-WAN campaign |
| filename | `loot_run.sh` | Credential stealer script in SD-WAN intrusion |
| filename | `vconfd_script_upload_tenant_list.sh` | Unauthorized script execution during CVE-2026-20245 exploitation |
| url | `http://13.62.52.206:5004` | C2 server hosting tool used in SD-WAN attack |
| url | `http://83.229.126.195:8081/xmrig` | XMRig payload download URL from SD-WAN cluster 7 |
| url | `http://83.229.126.195:8081/config.json` | XMRig config download URL from SD-WAN cluster 7 |
| url | `https://1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev/download` | Download URL for Nim-based backdoor, SD-WAN cluster 8 |
| filename | `auth.log` | Cisco SD-WAN log audited for CVE-2026-20127 exploitation evidence |
| filename | `serviceproxy-access.log` | Cisco SD-WAN Manager log under /var/log/nms/containers/service-proxy for CVE-2026-76504 investigation |
| filename | `vmanage-server.log` | Cisco SD-WAN Manager log under /var/log/nms/ for CVE-2026-76504 investigation |
**IOC Sweep Queries (Splunk):**
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("176.65.139.31") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("38.181.52.89") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("89.125.244.33") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("89.125.244.51") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("71.80.85.135") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("212.83.162.37") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("38.60.214.92") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("65.20.67.134") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("104.233.156.1") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("194.233.100.40") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("194.163.175.135") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("23.27.143.170") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("83.229.126.195") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("13.62.52.206") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("79.135.105.208") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_http) ("47.104.248.7") | stats count by sourcetype, id.orig_h, id.resp_h, id.resp_p | sort -count
index=corelight (sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev" OR "worf.replit.dev") | stats count by sourcetype, id.orig_h, query, server_name, host_header | sort -count
index=corelight (sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev") | stats count by sourcetype, id.orig_h, query, server_name, host_header | sort -count
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "d94f75a70b5cabaf786ac57177ed841732e62bdcc9a29e06e5b41d9be567bcfa" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "02654acfb21f83485393ba8b14bd8862b919b9ec966fc6768f6aac1338a45ee8" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "18d77c9c5bbb5b9d5bdfd366fdfcf26bad9e64c63ca865fad711bcce8e3d5a80" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2" | stats count by ComputerName, FileName, FilePath
index=crowdstrike (sourcetype="CrowdStrike:Event:Streams:JSON" OR sourcetype="crowdstrike:events:sensor") "4200b46a93c6ab059e2b34ce200c4a5b" | stats count by ComputerName, FileName, FilePath
index=corelight sourcetype=corelight_http uri="20251117022131.jsp" | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=corelight sourcetype=corelight_http uri="conf.jsp" | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=corelight sourcetype=corelight_http uri="sysv.jsp" | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=corelight sourcetype=corelight_http uri="sysinit.jsp" | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=corelight sourcetype=corelight_http uri="vmurnp_ikp.jsp" | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=linux-server (sourcetype=linux:audit OR sourcetype=audit) name="defunct.dat" | stats count by host, name, exe | sort -count
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=bash_history) ("miner.sh") | stats count by host, _raw | sort -count
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=bash_history) ("loot_run.sh") | stats count by host, _raw | sort -count
index=linux-server (sourcetype=linux:audit OR sourcetype=audit OR sourcetype=bash_history) ("vconfd_script_upload_tenant_list.sh") | stats count by host, _raw | sort -count
index=corelight sourcetype=corelight_http (id.resp_h="13.62.52.206" AND id.resp_p=5004) | stats count by id.orig_h, id.resp_h, uri, method | sort -count
index=corelight sourcetype=corelight_http (id.resp_h="83.229.126.195" AND id.resp_p=8081) | stats count by id.orig_h, uri, method | sort -count
index=corelight sourcetype=corelight_http (id.resp_h="83.229.126.195" AND id.resp_p=8081 AND uri="config.json") | stats count by id.orig_h, uri, method | sort -count
index=corelight (sourcetype=corelight_http OR sourcetype=corelight_ssl) ("1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev") | stats count by id.orig_h, id.resp_h, host_header, server_name, uri | sort -count
### YARA Rules
**UAT8616_SD_WAN_Webshells**: Detects known webshell filenames and content patterns deployed during Cisco SD-WAN exploitation campaigns including XenShell, Godzilla, and Behinder variants
rule UAT8616_SD_WAN_Webshells {
meta:
author = "RedSheepSec"
description = "Detects webshell filenames and patterns from Cisco SD-WAN exploitation campaigns"
reference = "https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/"
date = "2026-10-01"
severity = "critical"
strings:
$fn1 = "sysv.jsp" ascii
$fn2 = "conf.jsp" ascii
$fn3 = "sysinit.jsp" ascii
$fn4 = "vmurnp_ikp.jsp" ascii
$fn5 = "20251117022131.jsp" ascii
$fn6 = "cmd.gz.war" ascii
$fn7 = "defunct.dat" ascii
$s1 = "loot_run.sh" ascii
$s2 = "miner.sh" ascii
$s3 = "vconfd_script_upload_tenant_list.sh" ascii
$s4 = "XenShell" ascii nocase
condition:
any of them
}
**UAT8616_SD_WAN_Malware_Hashes**: Detects malware samples associated with Cisco SD-WAN exploitation clusters by SHA256 hash patterns
rule UAT8616_SD_WAN_Malware_Hashes {
meta:
author = "RedSheepSec"
description = "Detects known malware hashes from Cisco SD-WAN exploitation clusters (gsocket, Sliver, XMRig, kscan)"
reference = "https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/"
date = "2026-10-01"
severity = "critical"
strings:
$hash1 = { d9 4f 75 a7 0b 5c ab af 78 6a c5 71 77 ed 84 17 32 e6 2b dc c9 a2 9e 06 e5 b4 1d 9b e5 67 bc fa }
$hash2 = { 02 65 4a cf b2 1f 83 48 53 93 ba 8b 14 bd 88 62 b9 19 b9 ec 96 6f c6 76 8f 6a ac 13 38 a4 5e e8 }
$hash3 = { 96 fc 52 8c a5 e7 d1 c2 b3 ad d5 e3 1b 87 97 cb 12 6f 70 49 76 c8 fb ea ec db f0 aa 43 09 ad 46 }
$hash4 = { 18 d7 7c 9c 5b bb 5b 9d 5b df d3 66 fd fc f2 6b ad 9e 64 c6 3c a8 65 fa d7 11 bc ce 8e 3d 5a 80 }
condition:
any of them
}
### Suricata Rules
**SID 2026001**: Detects outbound connections to known UAT-8616/SD-WAN exploitation C2 IP 176.65.139.31
alert ip $HOME_NET any -> 176.65.139.31 any (msg:"HUNT UAT-8616 SD-WAN C2 IP 176.65.139.31"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026001; rev:1;)
**SID 2026002**: Detects outbound connections to Sliver C2 IP 23.27.143.170
alert ip $HOME_NET any -> 23.27.143.170 any (msg:"HUNT UAT-8616 Sliver C2 IP 23.27.143.170"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026002; rev:1;)
**SID 2026003**: Detects outbound connections to AdaptixC2 IP 194.163.175.135
alert ip $HOME_NET any -> 194.163.175.135 any (msg:"HUNT UAT-8616 AdaptixC2 IP 194.163.175.135"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026003; rev:1;)
**SID 2026004**: Detects outbound HTTP to XMRig payload host 83.229.126.195 on port 8081
alert http $HOME_NET any -> 83.229.126.195 8081 (msg:"HUNT SD-WAN XMRig Payload Host 83.229.126.195:8081"; flow:to_server,established; content:"xmrig"; http_uri; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026004; rev:1;)
**SID 2026005**: Detects DNS query for Nim backdoor download domain on replit.dev
alert dns $HOME_NET any -> any 53 (msg:"HUNT SD-WAN Nim Backdoor Download Domain worf.replit.dev"; dns.query; content:"worf.replit.dev"; nocase; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026005; rev:1;)
**SID 2026006**: Detects HTTP requests containing CVE-2026-76504 URI encoding bypass pattern
alert http any any -> $HOME_NET any (msg:"HUNT CVE-2026-76504 URI Encoding Bypass %6a_security_check"; flow:to_server,established; content:"%6a"; http_uri; content:"security_check"; http_uri; reference:url,www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/; classtype:web-application-attack; sid:2026006; rev:1;)
**SID 2026007**: Detects outbound connections to Behinder webshell deployment IP 212.83.162.37
alert ip $HOME_NET any -> 212.83.162.37 any (msg:"HUNT SD-WAN Behinder Deployment IP 212.83.162.37"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026007; rev:1;)
**SID 2026008**: Detects outbound connections to Godzilla webshell deployment IPs
alert ip $HOME_NET any -> [38.60.214.92,65.20.67.134,104.233.156.1,194.233.100.40] any (msg:"HUNT SD-WAN Godzilla Webshell Deployment IP"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026008; rev:1;)
**SID 2026009**: Detects outbound connections to SD-WAN exploitation source IPs (38.181.52.89, 89.125.244.33, 89.125.244.51)
alert ip $HOME_NET any -> [38.181.52.89,89.125.244.33,89.125.244.51] any (msg:"HUNT SD-WAN Exploitation Shell Interaction IPs"; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:trojan-activity; sid:2026009; rev:1;)
**SID 2026010**: Detects HTTP requests for known webshell JSP filenames deployed in SD-WAN exploitation
alert http any any -> $HOME_NET any (msg:"HUNT SD-WAN JSP Webshell Request sysv.jsp"; flow:to_server,established; content:"sysv.jsp"; http_uri; reference:url,blog.talosintelligence.com/sd-wan-ongoing-exploitation/; classtype:web-application-attack; sid:2026010; rev:1;)
**SID 2026011**: Detects path traversal deploying cmd.gz.war via SD-WAN software upload endpoint
alert http any any -> $HOME_NET any (msg:"HUNT SD-WAN Path Traversal cmd.gz.war Webshell Deploy"; flow:to_server,established; content:"cmd.gz.war"; http_uri; content:"deployments"; http_uri; reference:url,sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v; classtype:web-application-attack; sid:2026011; rev:1;)