wiz · Crawled Jul 22, 2026

Opening the Black Box: Agentless Threat Detection for Virtual Appliances

10 IoCs 3 Actors
Read original article ↗

AI Summary

FortiGate virtual appliances are being actively targeted by multiple threat actors due to their internet-facing nature and elevated privileges. Attackers exploit vulnerabilities such as CVE-2026-24858, CVE-2024-55591, and CVE-2022-41328 to gain access, create backdoor accounts, manipulate certificates, and establish lateral movement. These activities are often obscured by log deletion and weak configurations, making detection difficult without agentless visibility.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 10 extracted

Type Value Detail
IP 1[.]2[.]3[.]4 Details →
IP 144[.]31[.]1[.]252 Details →
IP 8[.]8[.]8[.]8 Details →
Domain openmail[.]pro Details →
Domain mail[.]io Details →
Domain tutamail[.]com Details →
Filename attacker-cert3 Details →
Filename backdoor-ssh Details →
Filename helpdesk Details →
Filename /bin/fgfm Details →

MITRE ATT&CK TTPs 23 techniques