logo

FortiClient Code Execution Vulnerability Exploited to Deploy EKZ Malware

ID: d234646e-a479-5431-9261-c8b17ad62281

STIX ID: report--d234646e-a479-5431-9261-c8b17ad62281

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Guru Baran

...
...

Arctic Wolf observed active exploitation of FortiClient EMS (CVE-2026-35616) where attackers bypassed API authentication to modify Remote Access Profiles and inject on_connect scripts that deploy a MinGW-compiled credential stealer named EKZ Infostealer to managed endpoints; the malware harvests browser credentials and session cookies and exfiltrates data to 83.138.53.110. The report includes process lineage, IOCs (IPs, SHA-256, filenames, payload URL), observed Tor-login correlation, and mitigation guidance including patching, restricting management access, auditing VPN scripts, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.