Back to all lessons
Awareness Lessons
4 months ago

FortiGate Firewalls Weaponized as Credential Harvesters in Mass Exploitation Campaign

Threat actors are actively exploiting unpatched vulnerabilities in Fortinet FortiGate firewalls, deploying a custom Golang-based sniffer to intercept and harvest credentials at massive scale — over 110 million credentials across approximately 430,000 devices. This campaign demonstrates how perimeter security devices, when left unpatched, can be inverted from defenders into active attack infrastructure. The severity is compounded by the fact that firewalls sit at the network boundary, giving attackers privileged visibility into all traffic passing through. Organizations that treat firewall firmware as a 'set and forget' component are especially exposed, as threat actors actively scan for known CVEs in widely deployed appliances. This incident underscores that no device — regardless of its security purpose — is immune to exploitation when patch discipline lapses.

Tactical Insight

Immediate actions

  • Apply the latest FortiOS patches and firmware updates to all FortiGate devices without delay, prioritizing internet-facing appliances.
  • Audit FortiGate management interfaces and restrict administrative access to trusted IP ranges only.
  • Rotate all credentials that may have transited or been managed through affected FortiGate devices.

Long-term improvements

  • Establish an automated vulnerability scanning program that continuously monitors all network appliances for known CVEs.
  • Maintain a comprehensive, up-to-date inventory of all network security devices including firmware versions and end-of-support dates.
  • Implement network segmentation so that firewall management planes are isolated from production traffic and user credential flows.

Detection measures

  • Deploy network traffic analysis tools to detect anomalous outbound data exfiltration originating from firewall devices.
  • Enable centralized logging of all FortiGate events and forward them to a SIEM for real-time alerting on suspicious configuration changes or unexpected process execution.
  • Subscribe to Fortinet's PSIRT advisories and threat intelligence feeds to receive early warning of newly disclosed vulnerabilities.