logo

Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls

ID: f194278c-1ac7-5b66-b115-2cc2664de3de

STIX ID: report--f194278c-1ac7-5b66-b115-2cc2664de3de

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2025-01-10

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs observed an active campaign exploiting publicly exposed FortiGate management interfaces—likely a zero-day later confirmed as CVE-2024-55591—where attackers used anomalous jsconsole logins (including spoofed loopback and DNS resolver IPs) to create super-admin accounts, modify SSL VPN portals to establish tunnels from VPS providers, and perform DCSync for credential harvesting; the report includes timelines, IoCs, TTP mappings, detection recommendations, and remediation advice (disable public management interfaces and patch firmware).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.