Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls
ID: f194278c-1ac7-5b66-b115-2cc2664de3de
STIX ID: report--f194278c-1ac7-5b66-b115-2cc2664de3de
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs observed an active campaign exploiting publicly exposed FortiGate management interfaces—likely a zero-day later confirmed as CVE-2024-55591—where attackers used anomalous jsconsole logins (including spoofed loopback and DNS resolver IPs) to create super-admin accounts, modify SSL VPN portals to establish tunnels from VPS providers, and perform DCSync for credential harvesting; the report includes timelines, IoCs, TTP mappings, detection recommendations, and remediation advice (disable public management interfaces and patch firmware).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
