Attackers exploiting a patched FortiClient EMS vulnerability in the wild
ID: 831d46ef-0958-542c-8aec-a7b834186779
STIX ID: report--831d46ef-0958-542c-8aec-a7b834186779
Feed Name: Securelist by Kaspersky
Date Published: 2024-12-19
Date Updated: 2026-04-29
Author: Ashley Muñoz, Francesco Figurelli, Cristian Souza, Eduardo Ovalle, Areg Baghinyan
Kaspersky GERT investigated active exploitation of a known FortiClient EMS SQL injection (CVE-2023-48788) where attackers used the flaw to download and run remote access tools (ScreenConnect, AnyDesk), deploy credential-stealing utilities (Mimikatz, webbrowserpassview, netpass), and conduct lateral movement and persistence; the report provides TTP mapping, IoCs (hashes, domains, IPs), telemetry of multi-country scanning and exploitation, and recommends patching to versions 7.0.11+/7.2.3+ and deploying MDR/alerting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
