logo

UNC5820 exploiting FortiManager flaw (Campaign)

ID: 3a8c2cd1-bf89-5593-ae2f-9306ede62fd0

STIX ID: report--3a8c2cd1-bf89-5593-ae2f-9306ede62fd0

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-10-24

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers identified active exploitation of a FortiManager zero-day (CVE-2024-47575) by UNC5820 beginning June 2024; the flaw in the fgfmd daemon enabled remote arbitrary command execution and was used to exfiltrate FortiGate configuration data (including credentials and policies). Compromised devices produced compressed files containing IP addresses and serial numbers and established outbound connections following file creation, with Fortinet issuing mitigations and updates to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.