logo

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

ID: b7a7073a-e2ef-524f-91ab-eaae4d3c76a8

STIX ID: report--b7a7073a-e2ef-524f-91ab-eaae4d3c76a8

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2024-11-15

Date Updated: 2026-05-01

...
...

Volexity reports that the BrazenBamboo actor developed and deployed modular Windows malware (DEEPDATA and DEEPPOST) and a Windows LIGHTSPY variant to collect and exfiltrate sensitive data; notably, a DEEPDATA plugin (msenvico.dll / FortiClient) exploited a zero‑day FortiClient VPN credential disclosure on Windows to harvest usernames, passwords, and server info from process memory. The analysis details plugin functionality (AccountInfo, FortiClient, WebBrowser, etc.), C2 infrastructure and URLs/ports, observed IOCs, a developer change log, and recommended detection rules and IOC blocklists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.