Threat actors are actively compromising Fortinet FortiGate devices to breach internal networks and steal sensitive service account credentials. These campaigns often target configuration files that contain encrypted or clear-text credentials for services like Active Directory (AD) and LDAP.
Key Exploitation Methods
Adversaries use a combination of known vulnerabilities and weak security hygiene to gain initial access:
- Vulnerability Exploitation: Attackers leverage critical flaws such as CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858 to bypass authentication.
- Weak Credentials: Many breaches occur due to exposed management ports and weak, single-factor credentials, which allow for automated brute-force attacks.
- AI-Augmented Attacks: Recent reports fromĀ AWS highlight actors using generative AI to automate mass scanning and configuration extraction at scale.
Post-Exploitation Activities
Once a device is compromised, attackers typically perform the following:
- Configuration Extraction: Stealing the device’s configuration file to harvest service account credentials and map network topology.
- Credential Harvesting: Decrypting configuration files to obtain clear-text credentials for accounts like
fortidcagent, which are then used to authenticate to the internal AD.
- Lateral Movement: Using stolen VPN or admin credentials to connect to internal networks, deploy remote management tools (e.g., Pulseway, MeshAgent), and access backup infrastructure.
- Persistence: Creating rogue local administrator accounts (e.g., “support”) and unrestricted firewall policies to maintain long-term access.
Recommended Mitigations
To defend against these intrusions, organizations should follow guidance from FortiGuard Labs and CISA:
- Immediate Patching: Update FortiOS and related firmware to the latest versions to address active SSO and authentication bypass flaws.
- Enforce MFA: Implement Multi-Factor Authentication for all administrative and VPN access.
- Restrict Access: Use local-in policies to limit administrative interface access to trusted IP addresses only.
- Credential Rotation: Reset and rotate all service account passwords, VPN credentials, and SSH keys if a compromise is suspected.