logo

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer

ID: 6b00a3cf-25c7-56f7-ad2c-0deb8893b32e

STIX ID: report--6b00a3cf-25c7-56f7-ad2c-0deb8893b32e

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-11-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Volexity reports that Beijing-linked APT "BrazenBamboo" is exploiting an unpatched FortiClient Windows VPN zero-day to deploy DeepData — a modular infostealer that includes a FortiClient plugin which extracts VPN usernames, passwords, gateways, and ports from process memory; DeepData (and related tools LightSpy/DeepPost) can also harvest credentials, browser data, messaging app data, audio, and files. Fortinet acknowledged the issue but no CVE or fix was assigned at the time; Volexity published detection rules and IOCs to mitigate ongoing exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.