KeyPlug Server Exposes Fortinet Exploits & Webshell Activity Targeting a Major Japanese Company
ID: cb88f3eb-2fb2-5e23-abd4-d007ab0b5758
STIX ID: report--cb88f3eb-2fb2-5e23-abd4-d007ab0b5758
Feed Name: Hunt.io Blog
Threat Score
A briefly exposed open directory on infrastructure attributed to RedGolf/APT41 and linked to KeyPlug revealed exploit scripts targeting Fortinet VPN/firewall (including WebSocket CLI exploits), a PHP AES/XOR webshell, PowerShell and Linux reverse shells, reconnaissance outputs (notably targeting Shiseido authentication and internal portals), and an HTTP-based session controller; the snapshot includes file hashes and IP/domain IOCs useful for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
