Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access
ID: 1c7751e7-088c-5721-bd4d-93144c7a9b84
STIX ID: report--1c7751e7-088c-5721-bd4d-93144c7a9b84
Feed Name: GBHackers
Researchers uncovered a sophisticated campaign compromising outdated FortiWeb appliances (versions ~5.4.202–6.1.62) using Sliver C2 and exploits including React2Shell (CVE-2025-55182) and probable FortiWeb zero-days; adversaries created decoy domains (ns1.ubunutpackages.store, ns1.bafairforce.army), established persistence via disguised systemd services and supervisor configs, and deployed FRP and a masqueraded SOCKS proxy bound to port 515 to enable lateral movement and covert proxying, with ~30 hosts onboarded primarily in Pakistan and Bangladesh (Dec 22–30, 2025), underscoring detection gaps for edge appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
