BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
ID: b7a7073a-e2ef-524f-91ab-eaae4d3c76a8
STIX ID: report--b7a7073a-e2ef-524f-91ab-eaae4d3c76a8
Feed Name: Volexity Blog
Volexity reports that the BrazenBamboo actor developed and deployed modular Windows malware (DEEPDATA and DEEPPOST) and a Windows LIGHTSPY variant to collect and exfiltrate sensitive data; notably, a DEEPDATA plugin (msenvico.dll / FortiClient) exploited a zero‑day FortiClient VPN credential disclosure on Windows to harvest usernames, passwords, and server info from process memory. The analysis details plugin functionality (AccountInfo, FortiClient, WebBrowser, etc.), C2 infrastructure and URLs/ports, observed IOCs, a developer change log, and recommended detection rules and IOC blocklists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
