Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls
ID: 4c13bcda-8466-558e-aab6-4bcecb6e19b0
STIX ID: report--4c13bcda-8466-558e-aab6-4bcecb6e19b0
Feed Name: Arctic Wolf
Date Published: 2025-01-10
Date Updated: 2026-07-27
Author: Stefan Hostetler, Julian Tuin, Trevor Daher, Jon Grimm, Alyssa Newbury, Joe Wedderspoon, and Markus Neis
Arctic Wolf Labs observed an active, opportunistic campaign exploiting FortiGate management interfaces (likely a zero-day later referenced as CVE-2024-55591) to perform unauthorised jsconsole administrative logins, create super-admin accounts, configure SSL VPN access from VPS-hosted IPs, and ultimately extract credentials via DCSync; defenders are urged to remove public-facing management interfaces, apply firmware updates, and hunt for the provided IoCs and jsconsole anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
