China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
ID: 6b00a3cf-25c7-56f7-ad2c-0deb8893b32e
STIX ID: report--6b00a3cf-25c7-56f7-ad2c-0deb8893b32e
Feed Name: The Register (Security)
Volexity reports that Beijing-linked APT "BrazenBamboo" is exploiting an unpatched FortiClient Windows VPN zero-day to deploy DeepData — a modular infostealer that includes a FortiClient plugin which extracts VPN usernames, passwords, gateways, and ports from process memory; DeepData (and related tools LightSpy/DeepPost) can also harvest credentials, browser data, messaging app data, audio, and files. Fortinet acknowledged the issue but no CVE or fix was assigned at the time; Volexity published detection rules and IOCs to mitigate ongoing exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
