logo

New infostealer reaches enterprise devices through FortiClient EMS vulnerability

ID: b922d6e9-aec9-5bfe-9a93-d1115cb104d9

STIX ID: report--b922d6e9-aec9-5bfe-9a93-d1115cb104d9

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Zeljka Zorz

...
...

Attackers exploited CVE-2026-35616 in FortiClient Enterprise Management Server to bypass API authentication and deliver a malicious FortiClient-managed update (FortiEndpoint_Patch.exe) that installs the EKZ Infostealer on endpoints; the infostealer harvests cookies, credentials and autofill data from Chromium- and Gecko-based browsers. Arctic Wolf observed the campaign in May 2026, recovered additional malicious samples from the threat actor’s server, shared IOCs, and advised organizations to check EMS logs, investigate suspicious accounts/configuration changes, and remediate by rotating credentials, revoking sessions, and taking recovery actions (e.g., reissuing payment cards if needed).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.