Detect Dell RecoverPoint for Virtual Machines (RP4VMs) Hard-coded Credentials Exploitation in Elastic Security
Detects exploitation of CVE-2026-22769, a hard-coded credentials vulnerability in Dell RecoverPoint for Virtual Machines (RP4VMs). Threat actors (including UNC6201) have actively exploited this zero-day to gain unauthorized access to RP4VMs appliances, enabling lateral movement, data exfiltration, and ransomware deployment within virtualized environments. The hard-coded credentials allow unauthenticated remote access to RP4VMs management interfaces.
MITRE ATT&CK
Elastic Detection Query
sequence by host.hostname with maxspan=5m
[authentication where
host.hostname like~ "*recoverpoint*" or host.hostname like~ "*rp4vm*" or host.hostname like~ "*rpa*"
and user.name in ("admin", "support", "boxmgmt", "root", "service", "recover")
and event.outcome == "success"
] by user.name
[process where
host.hostname like~ "*recoverpoint*" or host.hostname like~ "*rp4vm*"
and event.type == "start"
and process.name in ("bash", "sh", "python", "python3", "curl", "wget", "nc", "ncat")
] by user.name EQL sequence detecting a successful authentication on a Dell RP4VMs host using a known hard-coded username, followed within 5 minutes by process execution of a shell or network utility — indicating post-exploitation activity after CVE-2026-22769 abuse.
Data Sources
Required Tables
False Positives & Tuning
- Scheduled maintenance scripts run by default service accounts on RP4VMs nodes
- Legitimate administrators launching interactive shells post-authentication for configuration tasks
- Monitoring agents executing health-check scripts using default credentials before hardening
- Vendor-initiated diagnostic sessions spawning shell processes for log collection
Other platforms for CVE-2026-22769
Testing Methodology
Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1RP4VMs Default Credential SSH Authentication Simulation
Expected signal: SSH authentication event in /var/log/auth.log on the target RP4VMs appliance showing 'Accepted password for admin from <attacker_ip>'. SIEM should receive this via syslog forwarding from the appliance.
- Test 2RP4VMs Post-Exploitation Command Execution via Hard-coded Credentials
Expected signal: SSH session opened for user 'support' followed by process execution events (cat, ps, netstat/ss, find) visible in Auditd or Falco telemetry if deployed on the RP4VMs Linux host.
- Test 3RP4VMs Credential Discovery — Searching for Additional Credentials Post-Compromise
Expected signal: Auditd EXECVE syscall events for grep, cat, and env commands executed under the 'boxmgmt' user context on the RP4VMs host. File access events for /etc directory traversal.
- Test 4RP4VMs Persistence — Unauthorized SSH Key Installation
Expected signal: File write event to ~/.ssh/authorized_keys under the 'admin' user account on the RP4VMs host. Auditd or Falco should capture the open/write syscalls against the authorized_keys file path.
References (4)
- https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079
- https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa
- https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day
- https://nvd.nist.gov/vuln/detail/CVE-2026-22769
Unlock Pro Content
Get the full detection package for CVE-2026-22769 including response playbook, investigation guide, and atomic red team tests.