wiz · Crawled Jul 22, 2026
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
10 IoCs 3 Actors
Read original article ↗
AI Summary
FortiGate virtual appliances are being actively targeted by multiple threat actors due to their internet-facing nature and elevated privileges. Attackers exploit vulnerabilities such as CVE-2026-24858, CVE-2024-55591, and CVE-2022-41328 to gain access, create backdoor accounts, manipulate certificates, and establish lateral movement. These activities are often obscured by log deletion and weak configurations, making detection difficult without agentless visibility.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 1[.]2[.]3[.]4 | Details → |
| IP | 144[.]31[.]1[.]252 | Details → |
| IP | 8[.]8[.]8[.]8 | Details → |
| Domain | openmail[.]pro | Details → |
| Domain | mail[.]io | Details → |
| Domain | tutamail[.]com | Details → |
| Filename | attacker-cert3 | Details → |
| Filename | backdoor-ssh | Details → |
| Filename | helpdesk | Details → |
| Filename | /bin/fgfm | Details → |
MITRE ATT&CK TTPs 23 techniques
T1003.001 LSASS Memory · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.002 Domain Accounts · Defense Evasion T1087.002 Domain Account · Discovery T1095 Non-Application Layer Protocol · Command And Control T1098.002 Additional Email Delegate Permissions · Persistence T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1136.001 Local Account · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1499 Endpoint Denial of Service · Impact T1543.001 Launch Agent · Persistence T1556.004 Network Device Authentication · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1665 Hide Infrastructure · Command And Control