Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
Attackers are breaking into Fortinet's FortiGate VPN routers to install a stealthy spy program called PivotC2. This lets them spy on your network traffic and take control of your devices for months without you noticing.
- Report priority
- High
How it works
- Attackers send a specially crafted request to FortiGate VPN devices.
- This request tricks the router into running a hidden program that opens a backdoor.
- The backdoor lets the attackers secretly connect to your network, spy on your traffic, and install more malware.
- The attackers use this to keep control of your devices for a long time.
What to do
Check if you use a FortiGate VPN device by looking at your router's version number. If it is FortiOS 7.4.1 or earlier, or 7.2.3 or earlier, your device is vulnerable. You can check your version by logging into your FortiGate admin panel and looking under System > Dashboard > Overview.
Update your FortiGate device to FortiOS 7.4.2 or 7.2.4 immediately. Go to System > Admin > Firmware and install the latest version. If you can't update, contact Fortinet support for help. They can guide you through the process or provide a temporary fix if needed.
Technical details
Attackers first scan for FortiGate VPN devices connected to the internet. They then send a malicious request to the vulnerable device, which triggers the installation of PivotC2. Once installed, the attackers can monitor network traffic, steal data, and maintain persistent access to the compromised network.
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persistent post-exploitation of FortiOS appliances.