Malicious vmanage-admin Public Key Authentication in SSH Auth Log

PremiumReviewedSigma · High · v1
Product
linux
Service
sshd
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects SSH authentication events accepting a public key for the vmanage-admin account, an indicator of post-exploitation persistence on Cisco SD-WAN appliances following CVE-2026-20127. Adversaries add their own SSH key and authenticate as vmanage-admin to maintain root-equivalent access and pivot between appliances. Unexpected vmanage-admin key logins from unknown sources signal compromise.

Related detections9 linkedT1021.004 — drag to rearrange
Suspicious SSH authorized_keys Modification for Persistence
Malicious Immutable Attribute Set on SSH Authorized Keys via chattr on Linux
Malicious Bad Apples Remote Apple Events Lateral Movement via osascript
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
Suspicious SSH authorized_keys Persistence Modification (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Malicious EtherRAT SSH authorized_keys Backdoor Injection via Shell (via process_creation)
Malicious vmanage-admin Public Key Authentication in SSH Auth Log
Pivot detection · T1021.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.