logo

Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access

ID: 1c7751e7-088c-5721-bd4d-93144c7a9b84

STIX ID: report--1c7751e7-088c-5721-bd4d-93144c7a9b84

Feed Name: GBHackers

Threat Score
76/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers uncovered a sophisticated campaign compromising outdated FortiWeb appliances (versions ~5.4.202–6.1.62) using Sliver C2 and exploits including React2Shell (CVE-2025-55182) and probable FortiWeb zero-days; adversaries created decoy domains (ns1.ubunutpackages.store, ns1.bafairforce.army), established persistence via disguised systemd services and supervisor configs, and deployed FRP and a masqueraded SOCKS proxy bound to port 515 to enable lateral movement and covert proxying, with ~30 hosts onboarded primarily in Pakistan and Bangladesh (Dec 22–30, 2025), underscoring detection gaps for edge appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.