logo

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal Credentials (Campaign)

ID: 7b94b716-49aa-5fef-a7db-3f9cdadf68d0

STIX ID: report--7b94b716-49aa-5fef-a7db-3f9cdadf68d0

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2024-11-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

BrazenBamboo, a Chinese state‑affiliated APT, has been observed exploiting a zero‑day in Fortinet's FortiClient Windows VPN to harvest credentials from process memory via a DEEPDATA plugin; the report details the group's malware families (DEEPDATA, DEEPPOST, LIGHTSPY), credential theft and data exfiltration capabilities, overlapping C2 infrastructure, and indications of government-focused operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.