logo

FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

ID: 38398896-89a7-50ed-8e80-6953387bc358

STIX ID: report--38398896-89a7-50ed-8e80-6953387bc358

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers warn of an active campaign abusing FortiGate NGFW devices—via known CVEs and misconfigurations—to extract config files and service account credentials, which were then used to authenticate to Active Directory, enroll rogue workstations, deploy remote access tools, and exfiltrate NTDS.dit and SYSTEM hives (data sent to 172.67.196.232 over TCP/443). Targets include healthcare, government, and MSP environments; attackers demonstrated behaviors consistent with initial access brokers and possible pre-ransomware activity, while inadequate firewall logging hampered forensic visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.