logo

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

ID: acb90765-42bd-5aca-bdb8-491c3af0f82c

STIX ID: report--acb90765-42bd-5aca-bdb8-491c3af0f82c

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Arctic Wolf observed exploitation of CVE-2026-35616 in FortiClient EMS to distribute EKZ Infostealer by pushing a malicious update ('FortiEndpoint_Patch.exe') and Base64-encoded PowerShell scripts through EMS; the malware harvests browser cookies, saved credentials and autofill data, writes logs to ProgramData, and exfiltrates captured data via an HTTP POST to 83.138.53.110, while attackers modified EMS configurations and remote access profiles to push commands to all managed endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.