logo

Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls

ID: 4c13bcda-8466-558e-aab6-4bcecb6e19b0

STIX ID: report--4c13bcda-8466-558e-aab6-4bcecb6e19b0

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-01-10

Date Updated: 2026-07-27

Author: Stefan Hostetler, Julian Tuin, Trevor Daher, Jon Grimm, Alyssa Newbury, Joe Wedderspoon, and Markus Neis

...
...

Arctic Wolf Labs observed an active, opportunistic campaign exploiting FortiGate management interfaces (likely a zero-day later referenced as CVE-2024-55591) to perform unauthorised jsconsole administrative logins, create super-admin accounts, configure SSL VPN access from VPS-hosted IPs, and ultimately extract credentials via DCSync; defenders are urged to remove public-facing management interfaces, apply firmware updates, and hunt for the provided IoCs and jsconsole anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.