logo

KeyPlug Server Exposes Fortinet Exploits & Webshell Activity Targeting a Major Japanese Company

ID: cb88f3eb-2fb2-5e23-abd4-d007ab0b5758

STIX ID: report--cb88f3eb-2fb2-5e23-abd4-d007ab0b5758

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

A briefly exposed open directory on infrastructure attributed to RedGolf/APT41 and linked to KeyPlug revealed exploit scripts targeting Fortinet VPN/firewall (including WebSocket CLI exploits), a PHP AES/XOR webshell, PowerShell and Linux reverse shells, reconnaissance outputs (notably targeting Shiseido authentication and internal portals), and an HTTP-based session controller; the snapshot includes file hashes and IP/domain IOCs useful for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.