AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries
ID: f23fcffc-b692-59a8-ab15-8b4cd8d69a50
STIX ID: report--f23fcffc-b692-59a8-ab15-8b4cd8d69a50
Feed Name: The Hacker News
Amazon Threat Intelligence observed a financially motivated, Russian-speaking actor using commercial generative AI to scale attacks that compromised over 600 FortiGate appliances in 55 countries by scanning exposed management ports (443, 8443, 10443, 4443) and abusing weak/single-factor credentials. The actor extracted full device configurations, harvested Active Directory credentials, targeted Veeam backup servers, and deployed AI-assisted custom tooling (Go/Python) with artifacts and attack plans hosted on IP 212.11.64.250; activity aligns with preparatory steps for ransomware and shows AI enabling a low-skilled operator to operate at large scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
