logo

FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch

ID: c65eb0a6-b805-5edc-83bf-2d1b93b25bbb

STIX ID: report--c65eb0a6-b805-5edc-83bf-2d1b93b25bbb

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-06-11

...
...

Arctic Wolf Labs observed an active May 2026 campaign exploiting CVE-2026-35616 in FortiClient EMS to bypass API authentication and push malicious VPN/Remote Access Profile scripts that launched a MinGW-compiled credential stealer (EKZ Infostealer). The stealer harvests credentials, cookies, and autofill data from Chromium- and Firefox-family browsers, stages results locally and exfiltrates them to attacker-controlled infrastructure (notably 83.138.53.110); the report includes technical analysis, IOCs, detection guidance, and mitigation recommendations such as patching EMS and restricting access to management ports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.